2025年10月31日星期五

VMWare Products Multiple Vulnerabilities

VMWare Products Multiple Vulnerabilities

Release Date: 31 Oct 2025

RISK: Medium Risk

TYPE: Operating Systems - VM Ware

Multiple vulnerabilities were identified in VMware products.  A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, sensitive information disclosure and security restriction bypass on the targeted system.

 

Note:

CVE-2025-41244 is actively exploited in the wild. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM. Hence, the risk level is rated as Medium Risk.


Impact

  • Information Disclosure
  • Security Restriction Bypass
  • Elevation of Privilege

System / Technologies affected

  • VMware Aria Operations 8.x
  • VMware Tools 11.x.x, 12.x.x, 13.x.x
  • VMware Cloud Foundation 4.x, 5.x
  • VMware Telco Cloud Platform 4.x, 5.x
  • VMware Telco Cloud Infrastructure 2.x, 3.x
  • VMware Cloud Foundation Operations 9.x.x.x

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 


Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

Jenkins 多個漏洞

Jenkins 多個漏洞 發佈日期: 2026年03月20日 風險: 中度風險 類型: 伺服器 - 互聯網應用伺服器 於 Jenkins 發現多...