Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4316-1 | open-vm-tools security update |
EUVD |
EUVD-2025-31589 | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM. |
Ubuntu USN |
USN-7785-1 | Open VM Tools vulnerability |
Thu, 06 Nov 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware open Vm Tools
|
|
| CPEs | cpe:2.3:a:vmware:open_vm_tools:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:open_vm_tools:13.0.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Vmware open Vm Tools
|
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Debian
Debian debian Linux |
|
| CPEs | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Debian
Debian debian Linux |
Mon, 03 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 31 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Kernel Microsoft Microsoft windows Vmware cloud Foundation Operations Vmware telco Cloud Infrastructure Vmware telco Cloud Platform |
|
| CPEs | cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:cloud_foundation_operations:9.0:*:*:*:*:*:*:* cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux
Linux linux Kernel Microsoft Microsoft windows Vmware cloud Foundation Operations Vmware telco Cloud Infrastructure Vmware telco Cloud Platform |
Thu, 30 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
ssvc
|
Thu, 30 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Tue, 07 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 01 Oct 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-280 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 30 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Tue, 30 Sep 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware
Vmware aria Operations Vmware cloud Foundation Vmware tools |
|
| Vendors & Products |
Vmware
Vmware aria Operations Vmware cloud Foundation Vmware tools |
Mon, 29 Sep 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM. | |
| Title | VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246) | |
| Weaknesses | CWE-267 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-02-26T17:47:52.174Z
Reserved: 2025-04-16T09:30:17.799Z
Link: CVE-2025-41244
Updated: 2025-11-04T21:10:25.953Z
Status : Analyzed
Published: 2025-09-29T17:15:30.843
Modified: 2025-11-06T13:58:13.620
Link: CVE-2025-41244
OpenCVE Enrichment
Updated: 2025-09-30T08:48:28Z
Debian DLA
EUVD
Ubuntu USN