VMware released security advisories addressing multiple vulnerabilities affecting several of its products, including VMware Aria Operations and VMware Tools. The vulnerabilities, identified as CVE-2025-41244, CVE-2025-41245, and CVE-2025-41246, were disclosed in advisory VMSA-2025-0015. One of the most critical issues, CVE-2025-41244, is a local privilege escalation vulnerability that allows a malicious local user with non-administrative privileges to escalate their access to root on a virtual machine. This exploit is possible when VMware Tools is installed and managed by Aria Operations with SDMP enabled. The vulnerability has been rated with a CVSS score of 7.8, indicating a high severity risk. Affected products include VMware Aria Operations versions 8.x, VMware Tools versions 13.x.x, 12.x.x, and 11.x.x, as well as VMware Cloud Foundation, VMware NSX, VMware NSX-T, VMware Telco Cloud Infrastructure, VMware Telco Cloud Platform, VMware vCenter, and VMware vSphere Foundation. The advisory details that versions of VMware Tools prior to 13.0.5.0 and 12.5.4, and Aria Operations prior to 8.18.5, are vulnerable. VMware Cloud Foundation and Telco Cloud products are also impacted if running affected versions. The Canadian Centre for Cyber Security issued an alert urging users and administrators to review the advisories and apply the recommended mitigations. The vulnerabilities could allow attackers to gain full control over affected virtual machines, posing significant risks to organizations relying on VMware infrastructure. VMware has released patches and updates to address these vulnerabilities, and organizations are strongly advised to update their systems promptly. The advisories also provide links to further technical details and mitigation steps. The vulnerabilities are not known to be exploited in the wild at the time of disclosure, but the ease of local exploitation increases the urgency for remediation. Administrators are encouraged to verify their product versions and ensure that all affected systems are updated to the latest secure releases. The advisories highlight the importance of maintaining up-to-date virtualization infrastructure to prevent privilege escalation attacks. Organizations using VMware in cloud, telco, and enterprise environments should prioritize patching to mitigate potential threats. The coordinated disclosure and rapid release of patches demonstrate VMware's commitment to security and the need for vigilance among its user base.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2025-09-30, runZero published a blog post explaining how defenders can find VMware Aria installations on their networks, providing follow-on defensive guidance related to the advisory.
On 2025-09-30, the Center for Internet Security published an advisory highlighting that the VMware Aria Operations and VMware Tools flaws could allow privilege escalation.
On 2025-09-29, the vulnerabilities were reflected in CVE and downstream security advisories, including guidance from the Canadian Centre for Cyber Security urging administrators to review VMware advisories and apply mitigations.
On 2025-09-29, VMware released security advisory VMSA-2025-0015 addressing multiple vulnerabilities in VMware Aria Operations and VMware Tools, including CVE-2025-41244, CVE-2025-41245, and CVE-2025-41246.
6 references tracked. Mallory keeps watching after this page renders.
runzero.com
Open sourcecisecurity.org
Open sourcecyber.gc.ca
Open sourcecve.mitre.org
Open sourcesupport.broadcom.com
Open sourcesupport.broadcom.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.