VMware Tools和VMware Aria Operations都是美国威睿(VMware)公司的产品。VMware Tools是一款VMWare虚拟机自带的增强工具,它是VMware提供的用于增强虚拟显卡和硬盘性能、以及同步虚拟机与主机时钟的驱动程序。VMware Aria Operations是一个统一的、人工智能驱动的自动驾驶 IT 运营管理平台,适用于私有云、混合云和多云环境。 VMware Tools和VMware Aria Operations存在安全漏洞,该漏洞源于本地非特权攻击者可利
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| VMware | VCF operations | 9.0.x ~ 9.0.1.0 | - |
|
| VMware | VMware tools | 13.x.x.x ~ 13.0.5.0 | - |
|
| VMware | VMware Aria Operations | 8.18.x ~ 8.18.5 | - |
|
| VMware | VMware Cloud Foundation | 5.x ~ 8.18.5 | - |
|
| VMware | VMware Telco Cloud Platform | 5.x ~ 8.18.5 | - |
|
| VMware | VMware Telco Cloud Infrastructure | 3.x ~ 8.18.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Detection for CVE-2025-41244 | https://github.com/rxerium/CVE-2025-41244 | POC Details |
| 2 | VMware Aria Operations < 4.18.5 & VMware Tools - Local Privilege Escalation | https://github.com/haspiranti/CVE-2025-41244-PoC | POC Details |
| 3 | CVE-2025-41244 is a critical local privilege escalation vulnerability in VMware Aria Operations and VMware Tools | https://github.com/NULL200OK/CVE-2025-41244 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-41250 | 8.5 HIGH | Header injection vulnerability |
| CVE-2025-41251 | 8.1 HIGH | Weak password recovery vulnerability |
| CVE-2025-41246 | 7.6 HIGH | Improper authorisation vulnerability |
| CVE-2025-41252 | 7.5 HIGH | Username enumeration vulnerability |
| CVE-2025-41245 | 4.9 MEDIUM | VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabi |
No comments yet