CVE-2025-22230 is described as an “authentication bypass vulnerability” by Broadcom, allowing hackers to perform high-privilege operations without the necessary credentials. If you use VMware Tools ...
CISA added CVE-2025-41244 to KEV, mandating patching by November 20 The bug enables local privilege escalation via VMware Tools with SDMP enabled Chinese group UNC5174 exploited it for espionage ...
Broadcom has issued patches for a VMware vulnerability—CVE-2025-41244—that was already under exploitation by a China-linked hacking group, but failed to disclose that fact in its public advisory. The ...
There is a vulnerability in VMware Tools that allows attackers with low privileges in a VM to escalate their access rights. Broadcom has provided updated software to patch this vulnerability. VMware ...