Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-41244

Опубликовано: 29 сент. 2025
Источник: debian
EPSS Низкий

Описание

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
open-vm-toolsfixed2:13.0.5-1package
open-vm-toolsfixed2:12.5.0-2+deb13u1trixiepackage
open-vm-toolsfixed2:12.2.0-1+deb12u4bookwormpackage

Примечания

  • https://github.com/vmware/open-vm-tools/tree/CVE-2025-41244.patch

  • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149

EPSS

Процентиль: 75%
0.00915
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
4 месяца назад

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CVSS3: 7.8
nvd
4 месяца назад

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

suse-cvrf
3 месяца назад

Security update for open-vm-tools

suse-cvrf
3 месяца назад

Security update for open-vm-tools

suse-cvrf
4 месяца назад

Security update for open-vm-tools

EPSS

Процентиль: 75%
0.00915
Низкий