Back

HIGH KEV

VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)

Published Sep 29, 2025 ·Due Nov 20, 2025

Description

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Affected products

Remediation

Red Hat statement

This vulnerability was rated Important because, while it requires local code execution, the exploitation is trivial and leads to full compromise of privileged contexts such as root. The flaw lies in VMware’s service-discovery logic, which can execute attacker-controlled binaries from writable paths like /tmp. An unprivileged user who runs a process with a listening socket can have it invoked by the privileged discovery routine, resulting in arbitrary code execution. Only systems with guest service discovery enabled are affected; those without this feature configured are not exposed. Exploitation requires the service-discovery plugin (open-vm-tools-sdmp) to be installed. Red Hat CoreOS (RHCOS) is not affected, as it only ships the standard open-vm-tools package, which by default, does not include the -sdmp subpackage. Customers concerned about exposure should use the command `rpm -q open-vm-tools-sdmp` to verify whether the impacted package is present on their systems.

Red Hat mitigation

There are two main ways to eliminate the risk of this vulnerability: 1) Temporary - Disable the guest service discovery features: Disable the servicediscovery plugin in the config or by running the command `vmware-toolbox-cmd config set servicediscovery disabled true` then restart the system. 2) More permanent - Uninstall `open-vm-tools-sdmp` then restart the system.

Weaknesses (2)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published Sep 29, 2025
Updated Feb 26, 2026
Reserved Apr 16, 2025
CISA Vulnrichment
Updated Oct 30, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 29, 2025