Broadcom Patchs finally dangerous zero-day vmware operated by Chinese pirates


  • Broadcom Patches CVE-2025-41244, an escalation of high severity VMware privilege
  • Chinese actor UNC5174 operated the bug using malicious binaries in paths like / TMP / HTTPD
  • UNC5174 previously targeting the French government and the commercial sectors using Ivanti CSA vulnerabilities

Broadcom has corrected high severity vulnerability affecting its Aria VMware operations and VMware tools that have been used as a zero day in real world attacks.

In a new security notice, the company revealed to have set a vulnerability of local climbing of privileges which allowed a local user with limited access to a virtual machine to become root (if VMware tools and ARIA operations – with activated SDMP – operated on this virtual machine). The bug is now followed under the name of CVE-2025-41244 and has received a gravity score of 7.8 / 10 (high).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top