Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign Exploitation Wave Vulnerability

UNC5174 VMware privilege-escalation activity

Updated 31.10.2025 09:09
Case score 59
Case score 59 Members 3 Latest activity 31.10.2025 09:09
Active exploitation Public PoC/exploit reported KEV: CISA KEV Patch available
Members 3 First seen 30.09.2025 13:57 Last seen 01.10.2025 12:25 Updated 31.10.2025 09:09

Overview

UNC5174 is exploiting **CVE-2025-41244** against **VMware Aria Operations** and **VMware Tools** to move from local access to **root** on affected virtual machines. The activity has been active since October 2024 and uses malicious binaries staged in **/tmp/httpd** plus VMware service-discovery behavior to trigger privilege escalation. Broadcom and Linux vendors have released fixes, including updates for VMware environments and **open-vm-tools**. CISA added the flaw to the **Known Exploited Vulnerabilities** catalog and set **November 20, 2025** as the federal remediation deadline, while available evidence does not quantify how many organizations were affected.

Signals

9 derived
Exploitation
Exploitation Active exploitation CVSS 7.8 High Exploit Public PoC/exploit reported
CVEs/products
CVE
Victims/regions
Victim region United States
Remediation
KEV CISA KEV Remediation Patch available
Status
Campaign status Active
Threat context
Actor UNC5174

Member happenings

3 related
Campaign UNC5174 VMware CVE-2025-41244 exploitation campaign
Updated 01.10.2025 12:25 Lead Contribution 56
Campaign Active Patch Patch Available

The **UNC5174** operation is actively exploiting **CVE-2025-41244** to gain **root** code execution on VMware-managed virtual machines, increasing risk for organizations using **VMware Aria Operations**, **VMware Tools**, and **open-vm-tools**. The activity has persisted **since October 2024** and uses **malicious binaries in /tmp/httpd** plus discovery-logic abuse to trigger privilege escalation.

Exploitation Wave VMware Aria Operations and VMware Tools CVE-2025-41244 exploitation wave
Updated 30.09.2025 17:54 Scoring Support Contribution 3
Exploitation Active Exploitation CVSS 7.8 High Patch Patch Available

A **CVE-2025-41244** exploitation wave has affected **VMware Aria Operations** and **VMware Tools** since **mid-October 2024**, creating **privilege-escalation** risk on vulnerable VMs. Attackers can stage a malicious binary in broadly matched paths and push it into VMware service discovery, which can end in **root-level code execution**. A **proof-of-concept exploit** now shows how the flaw can be abused in both **credential-based** and **credential-less** configurations. The activity matters because it turns a local foothold into full administrative control on exposed systems.

Vulnerability VMware Tools and VMware Aria Operations local privilege escalation actively exploited (CVE-2025-41244)
Updated 30.09.2025 13:57 Context
Exploitation Active Exploitation Exploit Public Exploit Data Type Physical Addresses CVSS 7.8 High +1

**CVE-2025-41244** is a **local privilege escalation** flaw in **VMware Tools** and **VMware Aria Operations** that can let an unprivileged local user reach **root** on affected virtual machines. **Broadcom** and **NVISO** said the bug was exploited in the wild as a **zero-day** beginning in **mid-October 2024**, with abuse linked to **UNC5174**. The issue affects multiple **VMware** product lines, including **VMware Cloud Foundation**, **VMware vSphere Foundation**, and **Telco Cloud** deployments, and Broadcom said remediation requires **patching** with product-specific updates.