Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Warns of VMware Tools and Aria Operations 0-Day Vulnerability Exploited in Attacks

CISA Warns of VMware Tools and Aria Operations 0-Day Vulnerability Exploited in Attacks

Posted on October 31, 2025October 31, 2025 By CWS

The Cybersecurity and Infrastructure Safety Company (CISA) has added CVE-2025-41244 to its Recognized Exploited Vulnerabilities catalog. This native privilege escalation flaw impacts Broadcom’s VMware Aria Operations and VMware Instruments, with proof of lively exploitation within the wild.

Safety researchers and officers urge rapid patching to stop potential ransomware and different assaults that might compromise virtualized infrastructures.

The vulnerability, rated as Vital with a CVSSv3 base rating of seven.8, stems from a privilege outlined with an unsafe motion difficulty. It permits a malicious native actor with non-administrative entry to a digital machine (VM) to escalate their privileges to root on the identical VM.

That is significantly dangerous in setups the place VMware Instruments are put in and managed by Aria Operations with Software program-Outlined Administration Platform (SDMP) enabled.

Broadcom confirmed that suspected exploitation has already occurred, heightening considerations for organizations counting on VMware for cloud and on-premises virtualization.

At its core, CVE-2025-41244 exploits improper privilege-handling flaws in VMware Instruments and Aria Operations. A low-privileged person on a compromised VM can leverage this flaw to achieve full administrative management, probably pivoting to broader community entry or information exfiltration.

The assault requires native entry, that means preliminary footholds, similar to by means of phishing or unpatched endpoints, might function entry factors.

Broadcom’s evaluation ties the problem to CWE-267 (Privilege Outlined With Unsafe Actions), emphasizing how seemingly benign configurations can turn into assault surfaces. No workarounds exist, making well timed updates important.

Affected parts embody VMware Instruments variations previous to 12.5.4 and particular Aria Operations releases. For Linux customers, open-vm-tools updates will roll out through distributors, whereas Home windows 32-bit techniques are lined in Instruments 12.4.9 as a part of the 12.5.4 bundle.

CVE IDAffected ProductsCVSSv3 ScoreImpactFixed VersionsExploitation StatusCVE-2025-41244VMware Aria Operations, VMware Tools7.8 (Vital)Native privilege escalation to root on VMTools 12.5.4; Aria Operations patches per matrix; open-vm-tools through vendorsSuspected in-the-wild exploitation; added to CISA KEV catalog

Mitigations

CISA advises making use of vendor patches instantly and following Binding Operational Directive (BOD) 22-01 for federal cloud providers. Organizations unable to patch ought to contemplate discontinuing use of weak merchandise.

This incident underscores the persistent focusing on of virtualization platforms, which energy a lot of at the moment’s hybrid IT landscapes.

Broadcom credited Maxime Thiebaut of NVISO for locating and reporting the flaw, highlighting the position of collaborative safety analysis.

As ransomware campaigns more and more exploit such vulnerabilities, enterprises should prioritize vulnerability administration. With exploitation confirmed, unpatched techniques stay prime targets delaying motion might result in extreme operational disruptions.

Observe us on Google Information, LinkedIn, and X for every day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:0Day, Aria, Attacks, CISA, Exploited, Operations, Tools, VMware, Vulnerability, Warns

Post navigation

Previous Post: New Lampion Stealer Uses ClickFix Attack to Silently Steal Login Credentials
Next Post: Researchers Created a Linux Rootkit that Evades Elastic Security EDR Detection

Related Posts

Critical Grafana Vulnerability Let Attackers Escalate Privilege Critical Grafana Vulnerability Let Attackers Escalate Privilege Cyber Security News
Angular HTTP Client Vulnerability Exposes XSRF Token to an Attacker-Controlled Domain Angular HTTP Client Vulnerability Exposes XSRF Token to an Attacker-Controlled Domain Cyber Security News
Google Threat Intelligence Launches Actionable Technique To Hunt for Malicious .Desktop Files Google Threat Intelligence Launches Actionable Technique To Hunt for Malicious .Desktop Files Cyber Security News
Chrome 0-day Vulnerability Exploited in the Wild to Execute Arbitrary Code Chrome 0-day Vulnerability Exploited in the Wild to Execute Arbitrary Code Cyber Security News
Hackers Replace ‘m’ with ‘rn’ in Microsoft(.)com to Steal Users’ Login Credentials Hackers Replace ‘m’ with ‘rn’ in Microsoft(.)com to Steal Users’ Login Credentials Cyber Security News
Google’s Gemini Deep Research Tool Gains Access to Gmail, Chat, and Drive Data Google’s Gemini Deep Research Tool Gains Access to Gmail, Chat, and Drive Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News