# CVE-2025-41244

## Summary

- **CVE ID:** CVE-2025-41244
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-267
- **Published:** Sep 29, 2025
- **Last Modified:** Feb 26, 2026

## Description

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

## Affected Products

- VMware — VCF operations (9.0.x)
- VMware — VMware tools (13.x.x.x)
- VMware — VMware tools (12.5.x)
- VMware — VMware Aria Operations (8.18.x)
- VMware — VMware Cloud Foundation (5.x)
- VMware — VMware Cloud Foundation (4.x)
- VMware — VMware Telco Cloud Platform (5.x)
- VMware — VMware Telco Cloud Platform (4.x)
- VMware — VMware Telco Cloud Infrastructure (3.x)
- VMware — VMware Telco Cloud Infrastructure (2.x)

## References

- [CNA](http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149)
- [CISA-ADP](https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/)
- [CISA-ADP](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/10/msg00000.html)
- [CVE](http://www.openwall.com/lists/oss-security/2025/09/29/10)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 8.44%
- **EPSS Percentile:** 94.7

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Oct 30, 2025
- **Due Date:** Nov 20, 2025

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._