CVE-2025-41244

HIGH7.8⚠ KEVEPSS 0.53%

open-vm-tools - security update

發布日:2025/9/29修改日:2025/9/30加入 CISA KEV 日:2025/10/30
也稱為:DEBIAN-CVE-2025-41244DLA-4316-1

描述

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

參考連結(1)