Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
VMware Tools and Aria 0-Day Vulnerability Exploited for Privilege Escalation and Code Execution

VMware Tools and Aria 0-Day Vulnerability Exploited for Privilege Escalation and Code Execution

Posted on September 30, 2025September 30, 2025 By CWS

A zero-day native privilege escalation vulnerability in VMware Instruments and VMware Aria Operations is being actively exploited within the wild. The flaw, tracked as CVE-2025-41244, permits an unprivileged native attacker to realize root-level code execution on affected techniques.

On September 29, 2025, Broadcom disclosed the vulnerability, which exists inside VMware’s visitor service discovery options. Nonetheless, safety agency NVISO reported figuring out zero-day exploitation of this flaw courting again to mid-October 2024 throughout incident response engagements.

The vulnerability impacts each VMware Instruments and VMware Aria Operations, key elements used for managing virtualized environments. Profitable exploitation permits a person with low privileges to execute arbitrary code inside a privileged context, corresponding to the foundation person on Linux techniques.

The flaw impacts two distinct service discovery modes:

Credential-less service discovery: On this mode, the vulnerability lies inside the VMware Instruments part itself, which is broadly deployed on visitor digital machines.

Legacy credential-based service discovery: Right here, the flaw is positioned inside VMware Aria Operations, the administration platform for hybrid-cloud workloads.

NVISO researchers confirmed the flaw exists within the open-source variant of VMware Instruments, open-vm-tools, which is distributed with most main Linux distributions.

0-Day Vulnerability Exploitation

The basis reason behind CVE-2025-41244 is an Untrusted Search Path weak point (CWE-426) within the get-versions.sh script, which is liable for figuring out the variations of providers working on a digital machine.

The script makes use of overly broad common expressions to find service binaries. For instance, a sample like /S+/httpd is designed to search out the Apache internet server binary, however may also match a file named httpd positioned in a user-writable listing like /tmp.

An attacker can exploit this by putting a malicious executable at a path like /tmp/httpd. They then run this malicious course of and have it open a listening socket. When the VMware service discovery course of runs (usually each 5 minutes), it scans for working providers.

The flawed script will discover and execute the attacker’s malicious binary with the -v flag to get its model, but it surely does so with the elevated privileges of the VMware Instruments service. This gives the attacker with a root shell, granting them full management over the system.

NVISO has attributed the in-the-wild exploitation to UNC5174, a risk actor believed to be sponsored by the Chinese language state. This group has a historical past of leveraging public exploits for preliminary entry operations.

Nonetheless, researchers famous that as a result of trivial nature of the exploit and the widespread risk actor follow of naming malware after system binaries (e.g., httpd), it’s unclear if UNC5174 exploited the flaw deliberately or unintentionally. It’s potential that different malware has been unintentionally benefiting from this privilege escalation for years.

Organizations can detect exploitation by monitoring for uncommon youngster processes spawned by vmtoolsd or the get-versions.sh script. In credential-based mode, forensic proof could also be present in lingering script information positioned in /tmp/VMware-SDMP-Scripts-{UUID}/ directories.

Broadcom has launched patches and revealed a safety advisory to deal with CVE-2025-41244, and customers are urged to use the updates instantly.

Observe us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:0Day, Aria, Code, Escalation, Execution, Exploited, Privilege, Tools, VMware, Vulnerability

Post navigation

Previous Post: VMware Tools and Aria Operations Vulnerabilities Let Attackers Escalate Privileges to Root
Next Post: U.K. Police Just Seized £5.5 Billion in Bitcoin — The World’s Largest Crypto Bust

Related Posts

Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures Cyber Security News
CISA Warns of PHPMailer Command Injection Vulnerability Exploited in Attacks CISA Warns of PHPMailer Command Injection Vulnerability Exploited in Attacks Cyber Security News
Microsoft 365 Copilot Prompt Injection Vulnerability Allows Attackers to Exfiltrate Sensitive Data Microsoft 365 Copilot Prompt Injection Vulnerability Allows Attackers to Exfiltrate Sensitive Data Cyber Security News
Let’s Encrypt Temporarily Stops Certificate Issuance After Issue Let’s Encrypt Temporarily Stops Certificate Issuance After Issue Cyber Security News
PDFSIDER Malware Actively Used by Threat Actors to Bypass Antivirus and EDR Systems PDFSIDER Malware Actively Used by Threat Actors to Bypass Antivirus and EDR Systems Cyber Security News
Buterat Backdoor Attacking Enterprises to Establish Persistence and Control Endpoints Buterat Backdoor Attacking Enterprises to Establish Persistence and Control Endpoints Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • NGINX Vulnerability CVE-2026-42945 Actively Exploited
  • Grafana Labs GitHub Breach: Codebase Compromised by Hackers
  • Grafana Suffers GitHub Token Breach, Faces Extortion
  • Public macOS Kernel Exploit Found on Apple M5 Chip
  • Critical Flaw in Funnel Builder Targets WooCommerce

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • NGINX Vulnerability CVE-2026-42945 Actively Exploited
  • Grafana Labs GitHub Breach: Codebase Compromised by Hackers
  • Grafana Suffers GitHub Token Breach, Faces Extortion
  • Public macOS Kernel Exploit Found on Apple M5 Chip
  • Critical Flaw in Funnel Builder Targets WooCommerce

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark