Broadcom patches VMware Zero-Day actively exploited by UNC5174


Broadcom patches VMware Zero-Day actively exploited by UNC5174

Pierluigi Paganini
September 30, 2025

Broadcom patched six VMware flaws, including CVE-2025-41244, which has been exploited in the wild as a zero-day since mid-October 2024 by UNC5174

Broadcom addressed six VMware vulnerabilities, including four high-severity issues. One of these flaws, tracked as CVE-2025-41244 (CVSS score 7.8), allows local users to escalate to root via VMware Tools and Aria Operations.

“VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. Broadcom has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.8.” reads the advisory.A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.”

The vulnerability CVE-2025-41244 has been exploited in the wild as a zero-day since mid-October 2024 by the China-linked threat actor UNC5174.

“On September 29th, 2025, Broadcom disclosed a local privilege escalation vulnerability, CVE-2025-41244, impacting VMware’s guest service discovery features. NVISO has identified zero-day exploitation in the wild beginning mid-October 2024.” reads a report published by NVISO Labs. “Throughout its incident response engagements, NVISO determined with confidence that UNC5174 triggered the local privilege escalation. We can however not assess whether this exploit was part of UNC5174’s capabilities or whether the zero-day’s usage was merely accidental due to its trivialness. UNC5174, a Chinese state-sponsored threat actor, has repeatedly been linked to initial access operations achieved through public exploitation.”

The vulnerability impacts the following versions:

  • VMware Cloud Foundation 4.x and 5.x
  • VMware Cloud Foundation 9.x.x.x
  • VMware Cloud Foundation 13.x.x.x (Windows, Linux)
  • VMware vSphere Foundation 9.x.x.x
  • VMware vSphere Foundation 13.x.x.x (Windows, Linux)
  • VMware Aria Operations 8.x
  • VMware Tools 11.x.x, 12.x.x, and 13.x.x (Windows, Linux)
  • VMware Telco Cloud Platform 4.x and 5.x
  • VMware Telco Cloud Infrastructure 2.x and 3.x

Broadcom also fixed an Information disclosure vulnerability, tracked as CVE-2025-41245, and an improper authorisation vulnerability, tracked as CVE-2025-41246, in VMware products. The patches were released for Aria Ops, Tools, Cloud, and Telco.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Broadcom)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews



The Roku Sports interface now shows content you can watch on YouTube TV. The new feature, which is rolling out to all Roku devices in the U.S. starting today, will make it easier for fans to find games from YouTube TV, including all the NFL games that come with NFL Sunday Ticket.

Adding YouTube TV pushes Roku’s Sports section pretty far. The section already includes a bunch of other partners like DAZN Live Sports, FOX One, Frndly TV, Spectrum TV, and Xfinity Stream. The whole point is to give sports fans a central hub to find their favorite games, highlights, and scores from all the top leagues.

According to Joe Franzetta, Roku Media’s Head of Sports, the company’s main goal is to make “game time effortless for our users. Partnering with YouTube TV is a major step in delivering a comprehensive fan-centered experience that simplifies sports discovery and puts live action front and center for millions of fans.”

Roku also reported that YouTube TV will be available in other content discovery areas on the platform in the future. This means you’ll be able to find YouTube TV content in other sections that Rokue has, so you don’t miss out on anything important.

YouTube TV is a great app when it comes to live TV, but since the service added the NFL Sunday Ticket, it’s become a massive player in sports broadcasting. It’s also got some pretty sweet features for sports fans, like multiview, which lets you watch up to four games at once. It also has the ability to catch up on key plays, so you don’t have to worry if you’re running a little late. This integration will let YouTube TV subscribers make the most of their subscription by making it easy to find and jump into games.

You can still go straight to the YouTube TV app and look for your sports content there, since nothing will be changing on the app itself. The difference is that now you don’t need to look through the app to find its content, which makes it easier to find what you want since Roku’s sports interface saves a lot of time. I use it during the Super Bowl and on many Sundays. This is easier than trying to keep up with which company owns the right to broadcast the game I want to see.

Roku does offer a lot of content for free, but this does not mean the content shown on YouTube TV will be free. While you only need a Roku TV to get to the sports section, you still need a subscription to watch the content from YouTube TV. You also need the NFL Sunday Ticket for the NFL games included in the pass. It is just like the content shown by other broadcasters that is displayed in the Roku Sports section. So you’ll still need to pay the $85 month-to-month price, unless you took advantage of a promotion.

Source: Roku



Source link