VMware has issued a critical security advisory (VMSA-2025-0006) addressing a high-severity local privilege escalation vulnerability (CVE-2025-22231) in its Aria Operations platform. The flaw, rated 7.8 on the CVSSv3 scale, allows attackers with local administrative access to gain root-level control over affected systems. Attackers with existing local administrative privileges can exploit this flaw to execute arbitrary commands with root-level permissions, effectively granting full control over the appliance. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. Patches are now available for impacted products, including VMware Aria Operations, Cloud Foundation, and Telco Cloud platforms. Broadcom confirmed the severity as “Important,” noting that exploitation requires prior local access. The vulnerability stems from improper privilege containment mechanisms in VMware Aria Operations. Gurubaran is a co-founder of Cyber Security News and GBHackers On Security.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 01 Apr 2025 16:05:05 +0000