VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
| Vendor | Product | Versions |
|---|---|---|
| VMware | VCF operations | 9.0.x |
| VMware | VMware tools | 13.x.x.x, 12.5.x |
| VMware | VMware Aria Operations | 8.18.x |
| VMware | VMware Cloud Foundation | 5.x, 4.x |
| VMware | VMware Telco Cloud Platform | 5.x, 4.x |
| VMware | VMware Telco Cloud Infrastructure | 3.x, 2.x |
Yes — actively exploited. Added to the CISA KEV catalog on 2025-10-30. Ransomware use: Unknown.
For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.
Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice: