Broadcom finally patch the zero day of dangerous VMware exploited by Chinese pirates




  • BROADCOM PATCHES CVE-2025-41244, A High Severity VMware Privilege climber
  • The Chinese actor UNC5174 exploded the error using malicious binaries on routes such as /TMP /HTTPD
  • UNC5174 French government and commercial sectors previously attacked using Ivanti CSA vulnerabilities

Broadcom has poured high severity vulnerability that affects its VMware Aryan and VMware tools that apparently used as a zero day in real world attacks.

In a new security notice, the company revealed that it said that it set a vulnerability of local privileges that allowed a local user with limited access to a VM became root (if the VMware tools and the Aria operations, with enabled SDMP, were executed in that VM). The error is now tracked as CVE-2025-41244, and was given a gravity score of 7.8/10 (high).

Leave a Comment

Your email address will not be published. Required fields are marked *