logo

You name it, VMware elevates it (CVE-2025-41244)

ID: c325001b-8781-5687-9669-ba8963964200

STIX ID: report--c325001b-8781-5687-9669-ba8963964200

Feed Name: NVISO Labs

Threat Score
90/100

Date Published: 2025-09-29

Date Updated: 2026-04-28

Author: Maxime Thiebaut

...
...

**NVISO disclosure of CVE-2025-41244:** a trivial-to-exploit local privilege escalation in VMware Aria Operations and open-vm-tools service discovery that allows unprivileged processes (e.g., binaries staged in writable directories like /tmp) to be executed with privileged context (root). The report includes code-level analysis, a Go proof-of-concept that spawns an elevated shell, process-tree examples, detection suggestions, and notes active exploitation observed from mid‑October 2024 attributed to UNC5174; Broadcom published patches and an advisory on 2025-09-29.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.