LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-41244: Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 30, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 20, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-41244 to its Known Exploited Vulnerabilities catalog on Oct 30, 2025, with a federal patch deadline of Nov 20, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with…

CVE-2025-41244 is a privilege-defined-with-unsafe-actions flaw affecting Broadcom VMware Aria Operations and VMware Tools. A local non-administrative user on a virtual machine that has VMware Tools installed and is managed by Aria Operations with SDMP enabled can escalate privileges to root on that same VM. This matters because successful exploitation gives an attacker full control of the guest operating system, enabling further lateral movement, persistence, or data access inside the virtualized environment.

Organizations running Aria Operations to manage VMs that include VMware Tools should treat this as a high-priority local privilege-escalation risk and confirm exact impact and fixes against the vendor advisory.

How it works

The vulnerability is classified as CWE-267 (Privilege Defined with Unsafe Actions). In this class of weakness, a privileged component or service grants or exercises rights in a way that allows a lower-privileged caller to perform unintended high-privilege operations.

According to the public description, a malicious local actor who already possesses non-administrative privileges on a VM can abuse the interaction between VMware Tools and Aria Operations when SDMP is enabled. The result is escalation to root on that VM. No remote unauthenticated path is described; the attacker must already have a foothold on the guest. Exact abuse mechanics, required configuration flags, and any intermediate steps are not detailed in the available summary and must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

The products in scope are Broadcom VMware Aria Operations and VMware Tools. Typical deployments place Aria Operations as a management appliance or cluster that monitors and manages guest VMs; VMware Tools runs inside those guests to provide guest-host integration and management features.

Specific version ranges and exact SDMP prerequisites are not provided here; always validate against the official Broadcom advisory.

How to remediate

The primary remediation is to apply the vendor-supplied updates or mitigations for both Aria Operations and VMware Tools as directed in the Broadcom advisory. Follow the CISA-required action: apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for any cloud-hosted instances, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls focused on the local-escalation nature of the flaw.

These steps do not eliminate the vulnerability; they only lower the likelihood and impact of exploitation until a permanent fix is in place.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to full guest compromise and subsequent data exposure or ransomware staging, although ransomware use of this specific CVE is not documented. If you suspect a managed VM was escalated, isolate the guest, preserve forensic images, rotate credentials that may have been accessible from that VM, and review Aria Operations logs for signs of further abuse. As a general hygiene step, you can run a free exposure scan of your email addresses against known breach data to check whether any related accounts appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedBroadcom · VMware Aria Operations and VMware Tools
WeaknessCWE-267
Added to CISA KEVOct 30, 2025
Federal patch deadlineNov 20, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities