VYPR
Unrated severityCISA KEVNVD Advisory· Published Sep 29, 2025· Updated Feb 26, 2026

VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)

CVE-2025-41244

Description

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Affected products

6
  • VMware/VCF operationsv5
    Range: 9.0.x
  • VMware/VMware Aria Operationsv5
    Range: 8.18.x
  • VMware/VMware Cloud Foundationv5
    Range: 5.x
  • VMware/VMware Telco Cloud Infrastructurev5
    Range: 3.x
  • VMware/VMware Telco Cloud Platformv5
    Range: 5.x
  • VMware/VMware toolsv5
    Range: 13.x.x.x

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.