VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
Published Sep 29, 2025 ·Due Nov 20, 2025
7.8
HIGHCVSS 3.1
EPSS 8.44%
Description
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
Affected products
-
- Version 9.0.xStatusaffectedConstraints<9.0.1.0
- Version
-
- Version 8.18.xStatusaffectedConstraints<8.18.5
- Version
-
- Version 4.xStatusaffectedConstraints<8.18.5
- Version 5.xStatusaffectedConstraints<8.18.5
- Version
-
- Version 2.xStatusaffectedConstraints<8.18.5
- Version 3.xStatusaffectedConstraints<8.18.5
- Version
-
- Version 4.xStatusaffectedConstraints<8.18.5
- Version 5.xStatusaffectedConstraints<8.18.5
- Version
-
- Version 12.5.xStatusaffectedConstraints<12.5.4
- Version 13.x.x.xStatusaffectedConstraints<13.0.5.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| VMware | VCF operations | unaffected |
| |||||||||
| VMware | VMware Aria Operations | unaffected |
| |||||||||
| VMware | VMware Cloud Foundation | unaffected |
| |||||||||
| VMware | VMware Telco Cloud Infrastructure | unaffected |
| |||||||||
| VMware | VMware Telco Cloud Platform | unaffected |
| |||||||||
| VMware | VMware tools | unaffected |
|
Configuration 1
- ≥ 8.0 · < 8.18.5
- ≥ 4.0 · ≤ 5.2.2
- 9.0
- ≥ 11.2.0 · < 12.5.4
- 13.0.0
- ≥ 2.2 · ≤ 3.0
- ≥ 4.0 · < 5.0.1
Configuration 2
- 11.0
No data.
Red Hat Enterprise Linux 10
open-vm-tools-0:12.5.0-1.el10_0.1
Fixed · RHSA-2025:17429
Red Hat Enterprise Linux 8
open-vm-tools-0:12.3.5-2.el8_10.1
Fixed · RHSA-2025:17509
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
open-vm-tools-0:11.2.0-2.el8_4.5
Fixed · RHSA-2025:17512
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
open-vm-tools-0:11.2.0-2.el8_4.5
Fixed · RHSA-2025:17512
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
open-vm-tools-0:11.3.5-1.el8_6.6
Fixed · RHSA-2025:17511
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
open-vm-tools-0:11.3.5-1.el8_6.6
Fixed · RHSA-2025:17511
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
open-vm-tools-0:11.3.5-1.el8_6.6
Fixed · RHSA-2025:17511
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
open-vm-tools-0:12.1.5-2.el8_8.5
Fixed · RHSA-2025:17510
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
open-vm-tools-0:12.1.5-2.el8_8.5
Fixed · RHSA-2025:17510
Red Hat Enterprise Linux 9
open-vm-tools-0:12.5.0-1.el9_6.2
Fixed · RHSA-2025:17428
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
open-vm-tools-0:11.3.5-1.el9_0.6
Fixed · RHSA-2025:17452
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
open-vm-tools-0:12.1.5-1.el9_2.5
Fixed · RHSA-2025:17446
Red Hat Enterprise Linux 9.4 Extended Update Support
open-vm-tools-0:12.3.5-2.el9_4.1
Fixed · RHSA-2025:17445
Red Hat Enterprise Linux 7
open-vm-tools
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | open-vm-tools-0:12.5.0-1.el10_0.1 | Fixed | RHSA-2025:17429 |
| Red Hat Enterprise Linux 8 | open-vm-tools-0:12.3.5-2.el8_10.1 | Fixed | RHSA-2025:17509 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | open-vm-tools-0:11.2.0-2.el8_4.5 | Fixed | RHSA-2025:17512 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | open-vm-tools-0:11.2.0-2.el8_4.5 | Fixed | RHSA-2025:17512 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | open-vm-tools-0:11.3.5-1.el8_6.6 | Fixed | RHSA-2025:17511 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | open-vm-tools-0:11.3.5-1.el8_6.6 | Fixed | RHSA-2025:17511 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | open-vm-tools-0:11.3.5-1.el8_6.6 | Fixed | RHSA-2025:17511 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | open-vm-tools-0:12.1.5-2.el8_8.5 | Fixed | RHSA-2025:17510 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | open-vm-tools-0:12.1.5-2.el8_8.5 | Fixed | RHSA-2025:17510 |
| Red Hat Enterprise Linux 9 | open-vm-tools-0:12.5.0-1.el9_6.2 | Fixed | RHSA-2025:17428 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | open-vm-tools-0:11.3.5-1.el9_0.6 | Fixed | RHSA-2025:17452 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | open-vm-tools-0:12.1.5-1.el9_2.5 | Fixed | RHSA-2025:17446 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | open-vm-tools-0:12.3.5-2.el9_4.1 | Fixed | RHSA-2025:17445 |
| Red Hat Enterprise Linux 7 | open-vm-tools | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability was rated Important because, while it requires local code execution, the exploitation is trivial and leads to full compromise of privileged contexts such as root. The flaw lies in VMware’s service-discovery logic, which can execute attacker-controlled binaries from writable paths like /tmp. An unprivileged user who runs a process with a listening socket can have it invoked by the privileged discovery routine, resulting in arbitrary code execution. Only systems with guest service discovery enabled are affected; those without this feature configured are not exposed. Exploitation requires the service-discovery plugin (open-vm-tools-sdmp) to be installed. Red Hat CoreOS (RHCOS) is not affected, as it only ships the standard open-vm-tools package, which by default, does not include the -sdmp subpackage. Customers concerned about exposure should use the command `rpm -q open-vm-tools-sdmp` to verify whether the impacted package is present on their systems.
Red Hat mitigation
There are two main ways to eliminate the risk of this vulnerability: 1) Temporary - Disable the guest service discovery features: Disable the servicediscovery plugin in the config or by running the command `vmware-toolbox-cmd config set servicediscovery disabled true` then restart the system. 2) More permanent - Uninstall `open-vm-tools-sdmp` then restart the system.
References (11)
- http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149 Permissions Required
- http://www.openwall.com/lists/oss-security/2025/09/29/10 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2025-41244 Vendor Advisory
- https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ exploittechnical-descriptionThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2397752 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2025/10/msg00000.html Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-41244
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 vendor-advisoryVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2025-41244
Change history (0)
No recorded changes yet.