Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Warns of VMware Tools and Aria Operations 0-Day Vulnerability Exploited in Attacks

CISA Warns of VMware Tools and Aria Operations 0-Day Vulnerability Exploited in Attacks

Posted on October 31, 2025October 31, 2025 By CWS

The Cybersecurity and Infrastructure Safety Company (CISA) has added CVE-2025-41244 to its Recognized Exploited Vulnerabilities catalog. This native privilege escalation flaw impacts Broadcom’s VMware Aria Operations and VMware Instruments, with proof of lively exploitation within the wild.

Safety researchers and officers urge rapid patching to stop potential ransomware and different assaults that might compromise virtualized infrastructures.

The vulnerability, rated as Vital with a CVSSv3 base rating of seven.8, stems from a privilege outlined with an unsafe motion difficulty. It permits a malicious native actor with non-administrative entry to a digital machine (VM) to escalate their privileges to root on the identical VM.

That is significantly dangerous in setups the place VMware Instruments are put in and managed by Aria Operations with Software program-Outlined Administration Platform (SDMP) enabled.

Broadcom confirmed that suspected exploitation has already occurred, heightening considerations for organizations counting on VMware for cloud and on-premises virtualization.

At its core, CVE-2025-41244 exploits improper privilege-handling flaws in VMware Instruments and Aria Operations. A low-privileged person on a compromised VM can leverage this flaw to achieve full administrative management, probably pivoting to broader community entry or information exfiltration.

The assault requires native entry, that means preliminary footholds, similar to by means of phishing or unpatched endpoints, might function entry factors.

Broadcom’s evaluation ties the problem to CWE-267 (Privilege Outlined With Unsafe Actions), emphasizing how seemingly benign configurations can turn into assault surfaces. No workarounds exist, making well timed updates important.

Affected parts embody VMware Instruments variations previous to 12.5.4 and particular Aria Operations releases. For Linux customers, open-vm-tools updates will roll out through distributors, whereas Home windows 32-bit techniques are lined in Instruments 12.4.9 as a part of the 12.5.4 bundle.

CVE IDAffected ProductsCVSSv3 ScoreImpactFixed VersionsExploitation StatusCVE-2025-41244VMware Aria Operations, VMware Tools7.8 (Vital)Native privilege escalation to root on VMTools 12.5.4; Aria Operations patches per matrix; open-vm-tools through vendorsSuspected in-the-wild exploitation; added to CISA KEV catalog

Mitigations

CISA advises making use of vendor patches instantly and following Binding Operational Directive (BOD) 22-01 for federal cloud providers. Organizations unable to patch ought to contemplate discontinuing use of weak merchandise.

This incident underscores the persistent focusing on of virtualization platforms, which energy a lot of at the moment’s hybrid IT landscapes.

Broadcom credited Maxime Thiebaut of NVISO for locating and reporting the flaw, highlighting the position of collaborative safety analysis.

As ransomware campaigns more and more exploit such vulnerabilities, enterprises should prioritize vulnerability administration. With exploitation confirmed, unpatched techniques stay prime targets delaying motion might result in extreme operational disruptions.

Observe us on Google Information, LinkedIn, and X for every day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:0Day, Aria, Attacks, CISA, Exploited, Operations, Tools, VMware, Vulnerability, Warns

Post navigation

Previous Post: New Lampion Stealer Uses ClickFix Attack to Silently Steal Login Credentials
Next Post: Researchers Created a Linux Rootkit that Evades Elastic Security EDR Detection

Related Posts

New Vulnerabilities in Bluetooth Headphones Let Hackers Hijack Connected Smartphone New Vulnerabilities in Bluetooth Headphones Let Hackers Hijack Connected Smartphone Cyber Security News
Chinese APT Hackers Exploit Router Vulnerabilities to Infiltrate Enterprise Environments Chinese APT Hackers Exploit Router Vulnerabilities to Infiltrate Enterprise Environments Cyber Security News
VoidStealer Variant Evades Chrome Security Without Injection VoidStealer Variant Evades Chrome Security Without Injection Cyber Security News
10 Best Malware Analysis Tools 10 Best Malware Analysis Tools Cyber Security News
Threat Actors Merging FileFix and Cache Smuggling Attacks to Evade Security Controls Threat Actors Merging FileFix and Cache Smuggling Attacks to Evade Security Controls Cyber Security News
Heathrow and Other European Airports Hit by Cyberattack, Several Flights Delayed Heathrow and Other European Airports Hit by Cyberattack, Several Flights Delayed Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • India to Prohibit Chinese CCTV Sales by 2026
  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • India to Prohibit Chinese CCTV Sales by 2026
  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark