A zero-day vulnerability, which allows local privilege escalation and affects VMware Tools and VMware Aria Operations, is being actively exploited by cybercriminals. The bug, tracked as CVE-2025-41244, allows a local, unprivileged attacker to execute root-level code on affected systems.

Broadcom disclosed the vulnerability, which is located in guest service discovery features , on September 29, 2025. However, security firm NVISO reported that it has detected an exploit for this bug since mid-October 2024.
The vulnerability affects both VMware Tools and VMware Aria Operations, key components used to manage virtual environments. Successful exploitation could allow a low-privileged (such as the root user on Linux systems) to execute arbitrary code.
See also: Critical vulnerability in My Cloud NAS devices allows malicious code execution
The bug affects two different service discovery modes:
1. Credential-less service discovery: In this mode, the vulnerability lies in the VMware Tools component itself, which is widely installed on guest virtual machines.
2. Legacy credential-based service discovery: Here, the fault lies in VMware Aria Operations, the management platform for hybrid-cloud workloads.
NVISO researchers confirmed that the flaw exists in the open-source variant of VMware Tools, open-vm-tools, which is distributed with most major Linux distributions.
VMware Tools – VMware Aria Operations: Vulnerability Exploitation
The root cause of CVE-2025-41244 is an Untrusted Search Path weakness (CWE-426) in the get-versions.sh script, which is responsible for identifying the versions of services running on a virtual machine.
See also: CISA added Sudo vulnerability to KEV List

The script uses regular expressions to locate service binaries. For example, a pattern like /\S+/httpd is designed to find the Apache web server binary, but it will also match a file named httpd located in a user-writable directory like/tmp.
An attacker can exploit this by placing a malicious executable file in a path such as /tmp/httpd. They then execute this process and have it open on a listening socket. When the VMware service discovery process runs (usually every five minutes), it scans for running services.
The flawed script will find and execute the attacker's malicious executable with the -v flag to obtain its version, but it does so with the elevated privileges of the VMware Tools service. This provides the attacker with a root shell, giving them full control of the system.
See also: Security flaws in Tile allow location tracking
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
NVISO has attributed the exploitation of the vulnerability to the UNC5174, a threat actor believed to be funded by the Chinese state. This group has a history of leveraging public exploits for initial attempts to gain access to systems.

However, the researchers noted that due to the simple nature of the exploit and the common practice of threat actors to name their malware after system binaries (e.g. httpd), it is unclear whether UNC5174 exploited the flaw intentionally or accidentally. It is possible that other malware has inadvertently taken advantage of this privilege escalation for years.
Organizations can detect the exploit by monitoring for unusual child processes created by vmtoolsd or the get-versions.sh. In credential-based mode, evidence may be found in lingering script files that remain in the /tmp/VMware-SDMP-Scripts-{UUID}/ directories.
See also: WhatsApp: Vulnerability exploited via malicious DNG file
Broadcom has released patches and published a security advisory to address CVE-2025-41244. Therefore, users and organizations are urged to apply the updates immediately to protect their systems .
