HomeSecurityChinese hackers exploit VMware zero-day since October 2024

Chinese hackers exploit VMware zero-day since October 2024

A newly patched security vulnerability affecting Broadcom VMware Tools and VMware Aria Operationshas been exploited as a zero-day since mid- October 2024by a Chinese group known as UNC5174, NVISO Labs has concluded after an investigation.

Chinese hackers VMware zero-day

VMware: Which versions are affected?

The vulnerability is tracked as CVE-2025-41244 (CVSS score: 7.8), a local privilege escalation bug that affects the following versions:

– VMware Cloud Foundation 4.x and 5.x
– VMware Cloud Foundation 9.xxx
– VMware Cloud Foundation 13.xxx (Windows, Linux)
– VMware vSphere Foundation 9.xxx
– VMware vSphere Foundation 13.xxx (Windows, Linux)
– VMware Aria Operations 8.x
– VMware Tools 11.xx, 12.xx, and 13.xx (Windows, Linux)
– VMware Telco Cloud Platform 4.x and 5.x
– VMware Telco Cloud Infrastructure 2.x and 3.x

See also: CISA warns of vulnerability in Libraesva ESG

"A malicious local user with non-administrative privileges, who has access to a VM with VMware Tools installed, managed by Aria Operations, and SDMP enabled, can exploit this vulnerability to escalate privileges to root on the same VM," said in an advisory released Monday.

The fact that this is a local privilege escalation means that the adversary would have to gain access to the infected device in some other way.

NVISO researcher Maxime Thiebautdiscovered and reported the vulnerability on May 19, 2025, during an incident response. The company also reported that VMware Tools 12.4.9, which is part of VMware Tools 12.5.4, resolves the issue for Windows systems 32-bit. A version of open-vm-tools that addresses CVE-2025-41244 will be distributed by Linux vendors.

Chinese hackers exploit VMware zero-day since October 2024

While Broadcom does not report that the vulnerability has been used in actual attacks, NVISO Labs attributed the activity to a threat actor China-linked, which Google Mandiant tracks as UNC5174 (also known as Uteus or Uetus). The group has a history of exploiting various security vulnerabilities, including those affecting Ivanti and SAP NetWeaver. The vulnerabilities are used to gain initial access to target environments.

“When successful, the local privilege escalation exploit results in unprivileged users achieving code execution in privileged environments (e.g., root),” Thiebaut said. “We cannot, however, assess whether this exploit was part of the capabilities of UNC5174 or whether the use of the zero-day was simply accidental due to its simplicity.”

See also: Hacker sells exploit for Veeam vulnerability on the dark web

NVISO said the vulnerability starts with a function called “get_version()” that takes a regular expression (regex) pattern as input for each process with a listening socket, checks whether the binary associated with that process matches the pattern, and, if so, calls the version command of the supported service.

“While this functionality works as expected for system binaries (e.g., /usr/bin/httpd), the use of the broad-matching \S character class in many of the regex patterns also matches non-system binaries (e.g., /tmp/httpd),” Thiebaut explained. “These non-system binaries are located in directories (e.g., /tmp) that are writable by non-privileged users.”

Chinese hackers exploit VMware zero-day since October 2024

This opens the door to potential abuse by an unprivileged local attacker, placing the malicious binary in “/tmp/httpd,” resulting in privilege escalation when the VMware metrics collection service is executed. All a malicious user needs to do to exploit the vulnerability is ensure that the binary is executed by an unprivileged user and open a random listening socket.

See also: Hackers try to exploit vulnerability in PAN-OS GlobalProtect

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The Brussels-based cybersecurity firm noted that it observed the UNC5174 group using the “/tmp/httpd” location to place the malicious binary and create an elevated root shell and achieve code execution. The exact nature of the payload executed with this method is unclear at this stage.

“The widespread practice of impersonating system binaries (e.g., httpd) highlights the real possibility that several other malware strains have inadvertently taken advantage of unintended privilege escalations for years,” Thiebaut said.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS