CVE Vulnerabilities

CVE-2025-41244

Privilege Defined With Unsafe Actions

Published: Sep 29, 2025 | Modified: Nov 06, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Weakness

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Affected Software

NameVendorStart VersionEnd Version
Aria_operationsVmware8.0 (including)8.18.5 (excluding)
Cloud_foundationVmware4.0 (including)5.2.2 (including)
Cloud_foundation_operationsVmware9.0 (including)9.0 (including)
Open_vm_toolsVmware11.2.0 (including)12.5.4 (excluding)
Open_vm_toolsVmware13.0.0 (including)13.0.0 (including)
Telco_cloud_infrastructureVmware2.2 (including)3.0 (including)
Telco_cloud_platformVmware4.0 (including)5.0.1 (excluding)
Red Hat Enterprise Linux 10RedHatopen-vm-tools-0:12.5.0-1.el10_0.1*
Red Hat Enterprise Linux 8RedHatopen-vm-tools-0:12.3.5-2.el8_10.1*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatopen-vm-tools-0:11.2.0-2.el8_4.5*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatopen-vm-tools-0:11.2.0-2.el8_4.5*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatopen-vm-tools-0:11.3.5-1.el8_6.6*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatopen-vm-tools-0:11.3.5-1.el8_6.6*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatopen-vm-tools-0:11.3.5-1.el8_6.6*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatopen-vm-tools-0:12.1.5-2.el8_8.5*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatopen-vm-tools-0:12.1.5-2.el8_8.5*
Red Hat Enterprise Linux 9RedHatopen-vm-tools-0:12.5.0-1.el9_6.2*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatopen-vm-tools-0:11.3.5-1.el9_0.6*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatopen-vm-tools-0:12.1.5-1.el9_2.5*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatopen-vm-tools-0:12.3.5-2.el9_4.1*
Open-vm-toolsUbuntudevel*
Open-vm-toolsUbuntuesm-infra/focal*
Open-vm-toolsUbuntujammy*
Open-vm-toolsUbuntunoble*
Open-vm-toolsUbuntuplucky*
Open-vm-toolsUbuntuupstream*

Potential Mitigations

References