Latest VMware Aria Operations vulnerability: CVE-2025-41244 #
VMware has disclosed a local privilege escalation vulnerability in its VMware Aria Operations (formerly vRealize Operations) and VMware Tools. This flaw affects virtual machines (VMs) with VMware Tools installed that are managed by Aria Operations with the Service Discovery Management Pack (SDMP) enabled. A local adversary with low-level privileges on an affected VM could exploit this vulnerability to escalate their privileges to root and execute privileged code. The vulnerability impacts both legacy credential-based and credential-less discovery modes that use VMware Tools, including the open-source variant, open-vm-tools. This vulnerability has been designated CVE-2025-41244 and has been rated high with a CVSS score of 7.8.
The following versions are affected
- VMware Aria Operations 8.x versions prior to 8.18.5
- VMware Cloud Foundation (VCF) Operations 9.x.x.x versions prior to 9.0.1.0
- VMware Tools (including open-vm-tools) 13.x.x versions prior to 13.0.5
- VMware Tools (including open-vm-tools) 12.x.x and 11.x.x versions prior to 12.5.4
- VMware Cloud Foundation 5.x and 4.x versions with VMware Aria Operations component prior to 8.18.5
- VMware Telco Cloud Platform 5.x and 4.x versions with VMware Aria Operations component prior to 8.18.5
- VMware Telco Cloud Infrastructure 3.x and 2.x versions with VMware Aria Operations component prior to 8.18.5
What is the impact? #
Successful exploitation of these vulnerabilities would allow an adversary to execute arbitrary code on the vulnerable host, potentially leading to complete system compromise.
Are updates or workarounds available? #
Users are encouraged to update to the latest version as quickly as possible:
- VMware Aria Operations 8.x upgrade to version 8.18.5 or later
- VMware Cloud Foundation (VCF) Operations 9.x.x.x upgrade to version 9.0.1.0 or later
- VMware Tools (including open-vm-tools) 13.x.x upgrade to version 13.0.5 or later
- VMware Tools (including open-vm-tools) 12.x.x and 11.x.x upgrade to version 12.5.4 or later
- VMware Cloud Foundation 5.x and 4.x upgrade VMware Aria Operations component to version 8.18.5 or later
- VMware Telco Cloud Platform 5.x and 4.x upgrade VMware Aria Operations component to version 8.18.5 or later
- VMware Telco Cloud Infrastructure 3.x and 2.x upgrade VMware Aria Operations component to version 8.18.5 or later
How to find potentially vulnerable systems with runZero #
From the Service inventory, use the following query to locate potentially vulnerable assets:
_asset.protocol:http AND protocol:http AND has:last.html.title AND last.html.title:="VMware Aria Operations"