Improper access control in VMware Tools - CVE-2025-41244
Published: September 30, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the virtual machine.
The vulnerability exists due to improper access restrictions. A local non-privileged user on the virtual machine can execute arbitrary code with superuser privileges on the same virtual machine.
Note, the vulnerability is being exploited in the wild since mid-October 2024.
Affected software
IBM Qradar SIEM
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Manager Server 4.3
SUSE Manager Retail Branch Server 4.3
SUSE Manager Proxy 4.3
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Desktop Applications Module
Basesystem Module
Containers Module
openSUSE Leap
Ubuntu
Fedora
Juniper Secure Analytics (JSA)
VMware Aria Operations (formerly vRealize Operations)
IBM DataPower Gateway
open-vm-tools (Red Hat package)
open-vm-tools (Ubuntu package)
open-vm-tools-sdmp
open-vm-tools-desktop
open-vm-tools
open-vm-tools-salt-minion
libvmtools0-debuginfo
open-vm-tools-debuginfo
open-vm-tools-debugsource
libvmtools0
open-vm-tools-sdmp-debuginfo
open-vm-tools-desktop-debuginfo
open-vm-tools-containerinfo
libvmtools-devel
open-vm-tools-containerinfo-debuginfo
ExtremeCloud IQ Site Engine
How to mitigate CVE-2025-41244
IBM Qradar SIEM - update to 7.5.0 Update Pack 14 IF01
Juniper Secure Analytics (JSA) - update to 7.5.0 UP14 IF01
VMware Aria Operations (formerly vRealize Operations) - update to 8.18.5
IBM DataPower Gateway - update to 11.0.0.2
open-vm-tools (Red Hat package) - addressed in versions 11.2.0-2.el8_4.5, 11.3.5-1.el8_6.6, 11.3.5-1.el9_0.6, 12.1.5-1.el9_2.5, 12.1.5-2.el8_8.5, 12.3.5-2.el8_10.1, 12.3.5-2.el9_4.1, 12.5.0-1.el9_6.2, 12.5.0-1.el10_0.1
open-vm-tools (Ubuntu package) - addressed in versions 2:11.3.0-2ubuntu0~ubuntu20.04.8+esm1, 2:12.3.5-3~ubuntu0.22.04.3, 2:12.5.0-1ubuntu0.2, 2:12.5.0-1~ubuntu0.24.04.2
open-vm-tools-sdmp - update to 12.3.5-2
open-vm-tools-desktop - update to 12.3.5-2
open-vm-tools - update to 12.3.5-2
open-vm-tools-salt-minion - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
open-vm-tools-sdmp - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
open-vm-tools - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
libvmtools0-debuginfo - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
open-vm-tools-desktop - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
open-vm-tools-debuginfo - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
open-vm-tools-debugsource - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
libvmtools0 - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
open-vm-tools-sdmp-debuginfo - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
open-vm-tools-desktop-debuginfo - addressed in versions 13.0.0-4.89.1, 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-4.92.1, 13.0.5-150600.3.21.1
open-vm-tools-containerinfo - addressed in versions 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-150600.3.21.1
libvmtools-devel - addressed in versions 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-150600.3.21.1
open-vm-tools-containerinfo-debuginfo - addressed in versions 13.0.0-150300.64.1, 13.0.0-150600.3.18.1, 13.0.5-150600.3.21.1
open-vm-tools - addressed in versions 13.0.10-2.fc42, 13.0.10-2.fc43
ExtremeCloud IQ Site Engine - update to 25.11.10
External References
Related Security Bulletins
- Privilege escalation in VMware Tools
- Multiple vulnerabilitie in VMware Aria Operations
- Ubuntu update for open-vm-tools
- SUSE update for open-vm-tools
- SUSE update for open-vm-tools
- SUSE update for open-vm-tools
- Red Hat Enterprise Linux 10 update for open-vm-tools
- Red Hat Enterprise Linux 9 update for open-vm-tools
- Red Hat Enterprise Linux 9 update for open-vm-tools
- Red Hat Enterprise Linux 8 update for open-vm-tools
- Red Hat Enterprise Linux 8 update for open-vm-tools
- Red Hat Enterprise Linux 8 update for open-vm-tools
- Red Hat Enterprise Linux 8 update for open-vm-tools
- SUSE update for open-vm-tools
- Anolis OS update for open-vm-tools
- Red Hat Enterprise Linux 9 update for open-vm-tools
- Red Hat Enterprise Linux 9 update for open-vm-tools
- SUSE update for open-vm-tools
- Multiple vulnerabilities in IBM QRadar SIEM
- ExtremeCloud IQ - Site Engine update for VMware Tools
- Fedora 43 update for open-vm-tools
- Fedora 42 update for open-vm-tools
- Juniper Secure Analytics update for third-party components
- IBM DataPower Gateway update for VMware Aria Operations and VMware Tools