Skip to content
Threat Feed

Product

VMware Tools

4 briefs RSS
high threat

VMware Cloud Foundation, vSphere, Aria Operations, and Tools: Multiple Vulnerabilities

Multiple vulnerabilities exist in VMware Cloud Foundation, vSphere, Aria Operations, and VMware Tools, allowing an attacker to exploit these weaknesses to gain elevated privileges, including administrative access, and disclose confidential information within affected environments.

exploited VMware Cloud Foundation +3 virtualization cloud privilege-escalation
1t
high advisory

Potential CVE-2025-41244 vmtoolsd Local Privilege Escalation Attempt

Attackers can exploit CVE-2025-41244, a local privilege escalation vulnerability in VMware Tools' `vmtoolsd` service and its `get-versions.sh` script on Linux, by manipulating the `PATH` environment variable to execute malicious binaries with elevated privileges when the service attempts to retrieve version information, potentially leading to a root shell.

VMware Tools +1 privilege-escalation vmware linux vulnerability
1r 3t 1c
medium advisory

Persistence via Windows Installer (Msiexec)

Adversaries may establish persistence by abusing the Windows Installer (msiexec.exe) to create scheduled tasks or modify registry run keys, allowing for malicious code execution upon system startup or user logon.

Windows +21 persistence defense-evasion
3r 3t
medium advisory

Potential Persistence via Time Provider Modification

Adversaries may establish persistence by registering and enabling a malicious DLL as a time provider by modifying registry keys associated with the W32Time service.

Windows +1 persistence privilege-escalation time-provider
2r 2t