PoC Index

CVE-2025-41244

KEVHIGH 7.8EPSS 8.4%

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
8.44% chance of exploitation in the next 30 days, 95th percentile
CISA KEV
added 2025-10-30
Published
2025-09-29
Updated
2026-02-26

Proof-of-concept exploits (2)

References

Related