Unrated severityCISA KEVNVD Advisory· Published Sep 29, 2025· Updated Feb 26, 2026
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
CVE-2025-41244
Description
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
Affected products
6- VMware/VCF operationsv5Range: 9.0.x
- VMware/VMware Aria Operationsv5Range: 8.18.x
- VMware/VMware Cloud Foundationv5Range: 5.x
- VMware/VMware Telco Cloud Infrastructurev5Range: 3.x
- VMware/VMware Telco Cloud Platformv5Range: 5.x
- VMware/VMware toolsv5Range: 13.x.x.x
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.