Database/Kernel, userspace & hypervisor
VMware Aria Operations / VMware Tools: Local privilege escalation to root inside a managed VM via SDMP service discovery
CVSS 7.8CVE-2025-41244Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Local privilege escalation to root inside a managed VM via SDMP service discovery; exploited in the wild since Oct 2024 [KEV]
Who can reach it
Local non-admin user inside a managed guest VM
What to do
Update VMware Tools / Aria Operations in guest images; no host reboot
References
Related entries
- PAM (pam-config): Local user is treated as `allow_active` in PAMCVE-2025-6018 · PAM (pam-config)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (amd/amdkfd): A division by zero in the amdkfd (KFD compute driverCVE-2025-68174 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (amd/amdkfd)High
- Linux kernel (virt/kvm): KVM blocked turning KVM_MEM_GUEST_MEMFD on for an existing memslot but not turning it off, andCVE-2025-68810 · Linux kernel (virt/kvm)High
- Linux kernel (drivers/iommu): In an SVA context the IOMMU walks and caches the CPU's page tables, and on x86 everyCVE-2025-71089 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/gpu/drm/xe): The observation-config ioctl dereferences the config object after releasing the lockCVE-2025-71099 · Linux kernel (drivers/gpu/drm/xe)High
- libvirt: integer overflow in NodeGetFreePages gives a local user heap corruption in the root daemonCVE-2026-18917 · libvirt (NodeGetFreePages RPC handler)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.