{"id":"AZL-93039","summary":"CVE-2025-41244 affecting package open-vm-tools for versions less than 12.3.5-3","details":"VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.","modified":"2026-08-31T05:26:27Z","published":"2025-09-29T17:15:30Z","upstream":["CVE-2025-41244"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-41244"}],"affected":[{"package":{"name":"open-vm-tools","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/open-vm-tools"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.3.5-3"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93039.json"}}],"schema_version":"1.9.0"}