logo

Chinese hackers exploiting VMware zero-day since October 2024

ID: 0118877b-6b6e-5596-8456-25ed47d3dd2f

STIX ID: report--0118877b-6b6e-5596-8456-25ed47d3dd2f

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-09-30

Date Updated: 2026-07-19

Author: Sergiu Gatlan

...
...

Broadcom patched a high-severity privilege escalation zero-day (CVE-2025-41244) in VMware Aria Operations and VMware Tools that NVISO reports was exploited in the wild beginning mid-October 2024 by UNC5174; NVISO published a proof-of-concept showing how an unprivileged local attacker can stage a malicious binary (commonly in /tmp/httpd) and open a listening socket to escalate to root, and the report contextualizes this exploitation with UNC5174's prior supply-chain/network access activity and other recently patched VMware vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.