CVE-2025-41244General(debian / aria_operations)

LOWCVSS 7.8 · HIGHCISA KEV

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch debian aria_operations systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

1.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-11-20. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-267

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aria_operations
  • cloud_foundation
  • cloud_foundation_operations
  • debian_linux

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 4 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-08-20)
  • 5 total mentions across 4 days

Affected systems

Products
aria_operationscloud_foundationcloud_foundation_operationsdebian_linuxlinux_kernelopen_vm_toolstelco_cloud_infrastructuretelco_cloud_platformtoolswindows

4 versions affected across 10 products

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-07: 1Mentions · 2026-02-12: 1Mentions · 2026-04-13: 1Mentions · 2026-08-20: 2Patch / Workaround · 2026-08-20: 1Technical Details · 2026-02-07: 1Technical Details · 2026-04-13: 1Technical Details · 2026-08-20: 102-0702-1204-1308-20
Signal classification2 categories
General
480.0%
Disclosure
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-071
Disclosure1
2026-02-121
General1
2026-04-131
General1
2026-08-202
General2
Full discourse5 posts
  • reverseame@reverseame
    General

    You name it, VMware elevates it (CVE-2025-41244) #CVE202541244 #VMware #PrivilegeEscalation #ZeroDay #ServiceDiscovery https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/

    Post summary

    Tweet announces a new VMware zero‑day CVE‑2025‑41244 but offers no further details beyond a link.

    0401391.0K
    21.6K followersView on X
  • CVE Brief@DailyCVEBrief
    General

    LOOK BACK — VMware Tools shipped a discovery script that ran any listening binary matching /\S+/httpd as root, to read its version. /tmp/httpd matched. CVE-2025-41244 sat in open-vm-tools 5.5 years, and its finder can't say if the actor who tripped it meant to. https://t.co/AiEspdKDgN

    Post summary

    The tweet notes that a discovery script in VMware Tools flagged CVE‑2025‑41244 in open‑vm‑tools 5.5, but it gives no information on exploitation, patches, or a PoC.

    1000032
    29 followersView on X
  • DissentingSkeptic@DissentingS
    General

    @rxerium Im unable to DM directly. Its nuclei -t rxerium-templates/ -u https://host. I get [CVE-2025-41244] [http] [high] https://host/ui/login.action?vcf=1

    Post summary

    Nuclei scan output indicating detection of CVE-2025-41244 on https://host/ui/login.action?vcf=1, with no evidence of exploitation or mitigation.

    10000306
    261 followersView on X
  • CVE Brief@DailyCVEBrief
    General

    Full Look Back: the 2020 commit that shipped the flaw, the 2020 hardening commit that edited the same line and missed it, and why Broadcom deleted the feature instead of fixing the regex. https://cvebrief.com/cve/CVE-2025-41244/ https://t.co/DYGKn6rZG1

    Post summary

    The tweet gives a brief recap of how CVE-2025-41244 was introduced and missed during a hardening commit, and explains why Broadcom chose to remove the feature instead of fixing the underlying regex.

    0000023
    29 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    Critical security advisory for #Fedora administrators: CVE-2025-41244 represents a local privilege escalation vulnerability in open-vm-tools with CISA Major Incident designation. Read more: 👉 https://tinyurl.com/bjtnhc9f #Security https://t.co/Mg7rk9zwPH

    Post summary

    The advisory alerts Fedora administrators of CVE‑2025‑41244, a local privilege escalation flaw in open‑vm‑tools, and notes a CISA Major Incident rating.

    0000079
    1.3K followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
OSlinuxlinux_kernel---
OSmicrosoftwindows---
Appvmwarearia_operations---
Appvmwarecloud_foundation---
Appvmwarecloud_foundation_operations9.0--
Appvmwareopen_vm_tools---
Appvmwareopen_vm_tools13.0.0--
Appvmwaretelco_cloud_infrastructure---
Appvmwaretelco_cloud_platform---
Appvmwaretools---

Explore more