CVE-2025-41244

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Scoring

Severity
HIGH
CVSS base score
7.8
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS probability
8.44%
CISA KEV
Known exploited vulnerability
CWE
CWE-267
Published
2025-09-29
Last modified
2026-02-26

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs