Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CADOAh9e8bn-dbtCzLfMG26AXG_H_=sNVeocFiWLO2H2iEE4PyA@mail.gmail.com>
Date: Mon, 29 Sep 2025 21:47:31 +0530
From: VMware PSIRT <vmware.psirt@...adcom.com>
To: oss-security@...ts.openwall.com
Subject: [Security Advisory] open-vm-tools: Local privilege escalation (CVE-2025-41244)

Description
==============================================================
CVE-2025-41244: open-vm-tools contains a local privilege escalation
vulnerability. VMware has evaluated the severity of this issue to be
in the Important severity range with a maximum CVSSv3 base score of
7.8 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Known Attack Vectors
==============================================================
A malicious actor with non-administrative privileges on a guest VM may
exploit this vulnerability to escalate privileges to root on the same
VM.

Security Advisory
==============================================================
 VMSA-2025-0015 -
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149

Upstream fix for CVE-2025-41244
==============================================================
https://github.com/vmware/open-vm-tools/tree/CVE-2025-41244.patch

The following patches are provided for released versions of open-vm-tools:
- For all open-vm-tools versions 12.4.0, 12.4.5. 12.5.0, 13.0.0:
CVE-2025-41244-1240-1300-SDMP.patch
- For all open-vm-tools versions 12.3.0, 12.3.5:
CVE-2025-41244-1230-1235-SDMP.patch
- For all open-vm-tools versions 12.0.0, 12.0.5, 12.1.0, 12.1.5,
12.2.0, 12.2.5: CVE-2025-41244-1200-1225-SDMP.patch
- For all open-vm-tools versions 11.2.0, 11.2.5, 11.3.0, 11.3.5:
CVE-2025-41244-1120-1135-SDMP.patch

Thanks,
Praveen Singh
VMware Cloud Foundation PSIRT
Email: vmware.psirt@...adcom.com

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.