logo

CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers

ID: 1028565e-0151-5997-a30e-b34f086f91dc

STIX ID: report--1028565e-0151-5997-a30e-b34f086f91dc

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-10-30

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

CISA warned U.S. federal agencies to urgently patch CVE-2025-41244, a high-severity VMware Aria Operations/VMware Tools vulnerability that allows local non-admin users to escalate to root on affected VMs; the flaw was added to CISA's Known Exploited Vulnerabilities catalog and federal agencies have a mandated deadline to patch. Broadcom and researchers report active exploitation since October 2024 by UNC5174 (attributed to China/MSS), with proof-of-concept code available and observed attacks against defense contractors and government-related networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.