← Back to browse · API

CVE-2025-41244

Severity
HIGH
CVSS
7.8
EPSS
0.0788
Risk score
58.96
CISA KEV
Yes
PoC
No
Published
2025-10-30
Modified
2025-10-30
First seen
2026-08-07
Aliases
EUVD-2025-31589, GHSA-76FP-M4VP-HXRQ
Products
Broadcom:VMware Aria Operations and VMware Tools, VMware:VCF operations 9.0.x <9.0.1.0, VMware:VMware Aria Operations 8.18.x <8.18.5, VMware:VMware Cloud Foundation 4.x <8.18.5, VMware:VMware Cloud Foundation 5.x <8.18.5, VMware:VMware Telco Cloud Infrastructure 2.x <8.18.5, VMware:VMware Telco Cloud Infrastructure 3.x <8.18.5, VMware:VMware Telco Cloud Platform 4.x <8.18.5, VMware:VMware Telco Cloud Platform 5.x <8.18.5, n/a:VMware Tools 12.5.x <12.5.4, n/a:VMware Tools 13.x.x.x <13.0.5.0
Sources
cisa.gov CVE-2025-41244
euvd EUVD-2025-31589

Description

Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

References