A newly patched security flaw impacting Broadcom VMware Tools and VMware Aria Operations has been exploited in the wild as a zero-day since mid-October 2024 by a threat actor called UNC5174, according to NVISO Labs. The fact that it's a local privilege escalation means that the adversary will have to secure access to the infected device through some other means. The company also said VMware Tools 12.4.9, which is part of VMware Tools 12.5.4, remediates the issue for Windows 32-bit systems, and that a version of open-vm-tools that addresses CVE-2025-41244 will be distributed by Linux vendors. "When successful, exploitation of the local privilege escalation results in unprivileged users achieving code execution in privileged contexts (e.g., root)," Thiebaut said. As a result, this opens the door to potential abuse by an unprivileged local attacker by staging the malicious binary at "/tmp/httpd," resulting in privilege escalation when the VMware metrics collection service is executed.