Chinese hackers exploiting VMware zero-day since October 2024
ID: 0118877b-6b6e-5596-8456-25ed47d3dd2f
STIX ID: report--0118877b-6b6e-5596-8456-25ed47d3dd2f
Feed Name: Bleeping Computer
Broadcom patched a high-severity privilege escalation zero-day (CVE-2025-41244) in VMware Aria Operations and VMware Tools that NVISO reports was exploited in the wild beginning mid-October 2024 by UNC5174; NVISO published a proof-of-concept showing how an unprivileged local attacker can stage a malicious binary (commonly in /tmp/httpd) and open a listening socket to escalate to root, and the report contextualizes this exploitation with UNC5174's prior supply-chain/network access activity and other recently patched VMware vulnerabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
