Broadcom has released a series of security updates addressing multiple high-severity vulnerabilities across several VMware products, including VMware Tools, Aria Operations, vCenter, and NSX. The patched vulnerabilities include privilege escalation and information disclosure flaws that could allow attackers to gain elevated access or extract sensitive data from affected systems. In VMware Tools and Aria Operations, three vulnerabilities (CVE-2025-41244, CVE-2025-41245, CVE-2025-41246) were disclosed, which can be exploited to escalate privileges to root, steal credentials, and access other guest virtual machines. A zero-day proof-of-concept for a privilege escalation flaw in VMware Tools was published, with reports indicating that Chinese APT groups have leveraged this vulnerability in attacks. Broadcom also addressed two high-severity vulnerabilities in VMware NSX, reported by the U.S. National Security Agency (NSA), which allow unauthenticated attackers to enumerate valid usernames, potentially facilitating brute-force or unauthorized access attempts. Additionally, a high-severity SMTP header injection vulnerability (CVE-2025-41250) in VMware vCenter was patched, which could be exploited by attackers with non-administrative privileges to manipulate notification emails for scheduled tasks. The vulnerabilities in NSX and vCenter highlight the risk of unauthorized access and lateral movement within virtualized environments. Broadcom acknowledged the NSA's role in reporting the NSX flaws and emphasized the importance of timely patching. The company has a recent history of addressing critical VMware vulnerabilities, including those exploited as zero-days during the Pwn2Own Berlin 2025 hacking contest and others reported by the Microsoft Threat Intelligence Center. State-sponsored threat actors and cybercriminal groups, including ransomware operators, are known to actively target VMware vulnerabilities, increasing the urgency for organizations to apply these patches. The coordinated disclosure and rapid patching efforts underscore the ongoing threat landscape facing virtualization infrastructure. Organizations using VMware products are strongly advised to review Broadcom's security advisories and implement the recommended updates to mitigate the risk of exploitation. The vulnerabilities affect both on-premises and cloud-based VMware deployments, making comprehensive patch management essential. Security teams should also monitor for signs of exploitation, especially in environments where patching may be delayed. The publication of proof-of-concept exploits and reports of active targeting by advanced persistent threat groups further elevate the risk profile of these vulnerabilities. Broadcom's advisories provide detailed mitigation steps and highlight the collaborative efforts between vendors and security agencies to protect critical infrastructure. The breadth of affected products demonstrates the need for holistic security strategies in virtualized and cloud environments. Failure to address these vulnerabilities could result in significant compromise of sensitive systems and data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A Broadcom support portal security advisory entry associated with these VMware issues was published. This appears to be a later vendor advisory or notification record tied to the previously disclosed vulnerabilities.
Broadcom fixed multiple high-severity VMware NSX vulnerabilities that had been reported by the U.S. National Security Agency. Separate reporting on the same date also described Broadcom addressing multiple VMware vCenter and NSX issues.
Broadcom released fixes for vulnerabilities affecting VMware Tools and Aria Operations, including a privilege escalation issue and an information disclosure flaw. The patch release was reported on the same day as public coverage of the VMware Tools zero-day PoC.
A proof-of-concept exploit for a zero-day privilege escalation vulnerability affecting VMware Tools was published. Public release of exploit details increased the risk of broader abuse of the flaw.
A privilege escalation flaw in VMware Tools was reportedly used in the wild by a Chinese APT before public disclosure. The reporting indicates active exploitation preceded the later publication of a proof-of-concept and vendor patching.
5 references tracked. Mallory keeps watching after this page renders.
support.broadcom.com
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.