More

    Broadcom finally patches dangerous VMware zero-day exploited by Chinese hackers




    • Broadcom patches CVE-2025-41244, a high-severity VMware privilege escalation zero-day
    • Chinese actor UNC5174 exploited the bug using malicious binaries in paths like /tmp/httpd
    • UNC5174 previously targeted French government and commercial sectors using Ivanti CSA vulnerabilities

    Broadcom has patched a high-severity vulnerability affecting its VMware Aria Operations and VMware Tools that was apparently used as a zero-day in real-world attacks.

    In a new security advisory, the company revealed said it fixed a local privilege escalation vulnerability which allowed a local user with limited access to a VM to become root (if VMWare Tools and Aria Operations – with SDMP enabled – were running on that VM). The bug is now tracked as CVE-2025-41244, and was given a severity score of 7.8/10 (high).

    https://cdn.mos.cms.futurecdn.net/X5DPDeFcG3TSkqdJMgSU3U-970-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img