HomeSecurityCISA warns of vulnerability in VMware Tools and Aria Operations

CISA warns of vulnerability in VMware Tools and Aria Operations

The Cybersecurity and Infrastructure Security Agency (CISA) has added a VMware vulnerability (CVE-2025-41244) to its list of Known Exploitable Vulnerabilities (KEV). This local privilege escalation vulnerability affects Broadcom's VMware Aria Operations and VMware Tools , and there is evidence of active exploitation.

VMware

Security researchers and regulatory officials are urging immediate implementation of fixes to prevent potential ransomware attacks and other attacks that could compromise virtualized infrastructures.

The vulnerability, which has been rated 7.8 on the CVSSv3 scale, results from a privilege escalation defined as an “unsafe action issue.” It allows a malicious local user with non-administrative access to a virtual machine (VM) to escalate their privileges to root on the same VM.

See also: Windows Accessibility bug allows persistence and lateral movement

This is particularly dangerous in configurations where VMware Tools is installed and managed by Aria Operations with Software-Defined Management Platform(SDMP) enabled.

Broadcom has confirmed that a suspected exploit has already occurred, raising concerns for organizations that rely on VMware for cloud and on-premises virtualization.

CISA warns of vulnerability in VMware Tools and Aria Operations

VMware Tools and Aria Operations: Dangerous vulnerability

At its core, CVE-2025-41244 exploits privilege escalation vulnerabilities in VMware Tools and Aria Operations. A low-privileged user on a compromised VM could exploit this vulnerability to gain full administrative control, potentially allowing for broader network access or data extraction.

The attack requires local access.

Broadcom's analysis links the issue to CWE-267 (Privilege Defined With Unsafe Actions), highlighting how seemingly innocent configurations can become attack surfaces. There are no workarounds, making timely updates essential.

See also: Google Messages – Wear OS: Vulnerability allows apps to send SMS

Affected components include versions of VMware Tools prior to 12.5.4 and specific versions of Aria Operations. For Linux users, open-vm-tools updates will be released through vendors, while 32-bit Windows systems are covered in Tools version 12.4.9 as part of the 12.5.4 package.

CISA recommends immediate implementation of vendor patches, while federal cloud services are also urged to adhere to Binding Operational Directive (BOD) 22-01. Organizations that are unable to implement patches should consider discontinuing use of the vulnerable products.

CISA warns of vulnerability in VMware Tools and Aria Operations

This incident highlights the continued targeting of virtualization platforms, which power much of today's hybrid IT landscapes.

See also: CISA warns of vulnerabilities in DELMIA Apriso platform

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Broadcom credited NVISO's Maxime Thiebaut for discovering and reporting the vulnerability, emphasizing the role of collaborative security research.

As ransomware campaigns increasingly exploit such vulnerabilities, organizations must prioritize vulnerability management. With an exploit confirmed, unpatched systems remain prime targets; delaying action could lead to severe operational disruptions.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS