Improper access control in VMware Tools - CVE-2025-41244

 

Improper access control in VMware Tools - CVE-2025-41244

Published: September 30, 2025


Vulnerability identifier: #VU116185
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-41244
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local user to escalate privileges on the virtual machine. 

The vulnerability exists due to improper access restrictions. A local non-privileged user on the virtual machine can execute arbitrary  code with superuser privileges on the same virtual machine. 

Note, the vulnerability is being exploited in the wild since mid-October 2024.


Affected software

VMware Tools
IBM Qradar SIEM
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Manager Server 4.3
SUSE Manager Retail Branch Server 4.3
SUSE Manager Proxy 4.3
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Desktop Applications Module
Basesystem Module
Containers Module
openSUSE Leap
Ubuntu
Fedora
Juniper Secure Analytics (JSA)
VMware Aria Operations (formerly vRealize Operations)
IBM DataPower Gateway
open-vm-tools (Red Hat package)
open-vm-tools (Ubuntu package)
open-vm-tools-sdmp
open-vm-tools-desktop
open-vm-tools
open-vm-tools-salt-minion
libvmtools0-debuginfo
open-vm-tools-debuginfo
open-vm-tools-debugsource
libvmtools0
open-vm-tools-sdmp-debuginfo
open-vm-tools-desktop-debuginfo
open-vm-tools-containerinfo
libvmtools-devel
open-vm-tools-containerinfo-debuginfo
ExtremeCloud IQ Site Engine

How to mitigate CVE-2025-41244

Install updates from vendor's website.

VMware Tools - addressed in versions 12.5.4, 13.0.5.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 14 IF01
Juniper Secure Analytics (JSA) - update to 7.5.0 UP14 IF01
VMware Aria Operations (formerly vRealize Operations) - update to 8.18.5
IBM DataPower Gateway - update to 11.0.0.2
open-vm-tools (Red Hat package) - addressed in versions 11.2.0-2.el8_4.5, 11.3.5-1.el8_6.6, 11.3.5-1.el9_0.6, 12.1.5-1.el9_2.5, 12.1.5-2.el8_8.5, 12.3.5-2.el8_10.1, 12.3.5-2.el9_4.1, 12.5.0-1.el9_6.2, 12.5.0-1.el10_0.1
open-vm-tools (Ubuntu package) - addressed in versions 2:11.3.0-2ubuntu0~ubuntu20.04.8+esm1, 2:12.3.5-3~ubuntu0.22.04.3, 2:12.5.0-1ubuntu0.2, 2:12.5.0-1~ubuntu0.24.04.2
open-vm-tools-sdmp - update to 12.3.5-2
open-vm-tools-desktop - update to 12.3.5-2
open-vm-tools - update to 12.3.5-2
open-vm-tools-salt-minion - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
open-vm-tools-sdmp - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
open-vm-tools - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
libvmtools0-debuginfo - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
open-vm-tools-desktop - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
open-vm-tools-debuginfo - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
open-vm-tools-debugsource - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
libvmtools0 - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
open-vm-tools-sdmp-debuginfo - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
open-vm-tools-desktop-debuginfo - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
open-vm-tools-containerinfo - addressed in versions 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-150600.3.21.1
libvmtools-devel - addressed in versions 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-150600.3.21.1
open-vm-tools-containerinfo-debuginfo - addressed in versions 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-150600.3.21.1
open-vm-tools - addressed in versions 13.0.10-2.fc42, 13.0.10-2.fc43
ExtremeCloud IQ Site Engine - update to 25.11.10

External References

Related Security Bulletins