[CIVN-2025-0301] Multiple Vulnerabilities in VMware Products

By Published On: November 7, 2025

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in VMware Products 
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
VMware Aria Operations 8.x,
VMware Tools 12.x.x, 11.x.x,13.x.x
VMware Cloud Foundation 5.x, 4.x, 9.x.x.x, 13.x.x.x
VMware vSphere Foundation 9.x.x.x, 13.x.x.x
VMware Telco Cloud Platform 5.x, 4.x
VMware Telco Cloud Infrastructure 3.x, 2.x
Overview
Multiple vulnerabilities have been reported in VMware products, which could allow an attacker to gain unauthorised access, escalate privileges and gain access to credentials on the targeted system.
Target Audience:
Enterprises and large organisations, cloud service providers and industries with IT environments utilising VMware products.
Risk Assessment:
Risk of full system compromise, sensitive information disclosure and lateral movement.
Impact Assessment:
Potential for local privilege escalation, disclosure of sensitive information and unauthorised access.
Description
VMware provides virtualisation software solutions that enable organisations to create and manage virtual machines (VMs), allowing multiple operating systems to run on a single physical machine.
These vulnerabilities affect VMware products due to issues in VMware Tools, Aria Operations. An attacker could exploit these vulnerabilities by sending specially crafted requests.
Successful exploitation of these vulnerabilities could allow the attacker to escalate privileges to gain unauthorised access, escalate privileges and gain access to credentials on the targeted system.
Note: CVE-2025-41244 is being actively exploited in the wild.
Solution
Apply appropriate updates as mentioned by the vendor:
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149
Vendor Information
VMware
https://support.broadcom.com/web/ecx/security-advisory
References
VMware
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149
CVE Name
CVE-2025-41244
CVE-2025-41245
CVE-2025-41246
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmkODHUACgkQ3jCgcSdc
ys+PfA//bO4ZySmsbynPqu1Dd0neGMRApspThLLu5s3yxCbSlT2noE7xt5qmDN9z
hxG+IQk8bz2rp5F7NndsnxAs+QQPUtabK4/leD6rxN17LY1ow9tq2oYuL6CS3L8o
6oy2XbyJ8NQ8dy2UbIPut6/6Rz826yyWPvLtxj9g+6vdyXIKV2ipr+1ABou0it6s
Q2nNT/QGKgj+wKRPSM9K5SWFTF4CCUHEHCWiK/yKBfzvZJOX+SkWRgEgkcE8yiFE
lONsGjHGqnkjFSITh2fklTzewo07jWiBrBtEqGxe/rGQlQEQc6Vzc8Uy+9qqYxgn
+W6aeoKA7LsWBQ9YwY9KAHM2YoqXXK3m6kujkBbQroLy0V6AC9xZmywz+u2RwRa7
ryf7teB3Ux5cb7CkhaMgOcFT4+2Bw6fXLuzppCKidmAwK2emizFQok6hX1MYq5O0
a9BTZUZdvJk31Sv3NN3fMSeoLBEWADO9FIrPMokxAFHn/jVfbahzj9yPHFnDstwI
jMBsE+5JkkEbQ6lRZE2uttudIt9FrBuckNDX4D3PXxP0HxCW4AbFTChOCSWHZFXu
dDxJMmHSK6bcp80vQD90Ix9jKEZp6XBbEqGg3G8nsufldpWz37mJBxsKuOQFjZkh
9IQ8PUT1pUWXs7C17pUP4bm+9SNTd26N3g/PJ7Nad6pKzRfayPQ=
=doi1
—–END PGP SIGNATURE—–

Share this article