Executive Summary
In October 2024, China-linked threat actor UNC5174 actively exploited an undisclosed zero-day vulnerability (CVE-2025-41244) in Broadcom VMware Tools and VMware Aria Operations, primarily impacting VMware Cloud Foundation 4.x and 5.x. This local privilege escalation flaw allowed attackers to gain elevated access on affected systems, facilitating potential lateral movement across enterprise networks. The exploitation campaign remained undetected for several months until NVISO Labs and security researchers documented the sophisticated tactics, techniques, and persistence of UNC5174.
This incident highlights the growing risks associated with zero-day vulnerabilities in widely deployed virtualization platforms, especially as advanced persistent threats increasingly target cloud and hybrid infrastructure. The attack underscores the urgent need for robust patch management and east-west security controls amid a surge in sophisticated nation-state cyber activity.
Why This Matters Now
The VMware zero-day underscores significant exposure in critical cloud infrastructure environments, as attackers are targeting popular virtualization platforms at scale. The urgency stems from the active exploitation in the wild by a nation-state-linked APT, putting enterprise data and operations at immediate risk and requiring rapid detection, segmentation, and patching actions.
Attack Path Analysis
The adversary initially gained a foothold by exploiting a zero-day privilege escalation vulnerability (CVE-2025-41244) in VMware Tools/Aria Operations within the cloud environment. After initial compromise, they leveraged local privilege escalation to gain higher-level access on the affected workloads. Lateral movement followed, with the attacker pivoting between cloud workloads—potentially leveraging east-west internal traffic paths and Kubernetes clusters. The threat actor established command and control channels, likely using encrypted or covert outbound communication. Sensitive data was exfiltrated through egress channels, possibly via application-to-internet flows or by staging data within the environment for later extraction. The campaign culminated in potential impact scenarios such as service disruption or ransomware, enabled by high privileges within the cloud environment.
Kill Chain Progression
Initial Compromise
Description
UNC5174 exploited CVE-2025-41244 in VMware Tools/Aria Operations to gain an initial foothold within targeted cloud workloads.
Related CVEs
CVE-2025-41244
CVSS 7.8A local privilege escalation vulnerability in VMware Aria Operations and VMware Tools allows a malicious local actor with non-administrative privileges to escalate privileges to root on the same VM.
Affected Products:
VMware Aria Operations – 4.x, 5.x
VMware VMware Tools – 4.x, 5.x
Exploit Status:
exploited in the wildReferences:
https://nvd.nist.gov/vuln/detail/CVE-2025-41244https://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244CVE-2025-41245
CVSS 7.5An information disclosure vulnerability in VMware Aria Operations allows a malicious actor with non-administrative privileges to disclose credentials of other users.
Affected Products:
VMware Aria Operations – 4.x, 5.x
Exploit Status:
no public exploitReferences:
CVE-2025-41246
CVSS 7An improper authorization vulnerability in VMware Tools for Windows allows a malicious actor with non-administrative privileges on a guest VM to access other guest VMs.
Affected Products:
VMware VMware Tools for Windows – 4.x, 5.x
Exploit Status:
no public exploitReferences:
MITRE ATT&CK® Techniques
Exploitation for Privilege Escalation
Exploitation for Client Execution
Valid Accounts
Command and Scripting Interpreter
Indicator Removal on Host
Impair Defenses
Obfuscated Files or Information
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Address Common and Emerging Vulnerabilities
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Cybersecurity Risk Assessment
Control ID: 500.10
DORA – ICT Risk Management Measures
Control ID: Article 10.1
CISA ZTMM 2.0 – Minimize Privilege Escalation Vectors
Control ID: Identity Pillar: Credential and Authentication Management
NIS2 Directive – Technical and Organisational Measures
Control ID: Article 21(2)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
China-linked APT exploiting VMware zero-day since October 2024 creates critical infrastructure vulnerabilities requiring immediate zero trust segmentation and threat detection capabilities.
Financial Services
Advanced persistent threat targeting VMware infrastructure poses significant compliance risks under PCI DSS and requires enhanced east-west traffic security monitoring.
Health Care / Life Sciences
VMware privilege escalation vulnerability threatens HIPAA compliance and patient data protection, demanding multicloud visibility and encrypted traffic controls immediately.
Government Administration
State-sponsored threat actor exploiting VMware zero-day represents critical national security risk requiring comprehensive threat detection and anomaly response systems.
Sources
- Urgent: China-Linked Hackers Exploit New VMware Zero-Day Since October 2024https://thehackernews.com/2025/09/urgent-china-linked-hackers-exploit-new.htmlVerified
- VMware Aria Operations and VMware Tools updates address multiple vulnerabilitieshttps://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149Verified
- CVE-2025-41244 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-41244Verified
- CVE-2025-41244 Added to CISA's Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, workload-to-workload east-west controls, rigorous egress policy enforcement, and in-line threat/anomaly detection would have significantly constrained each stage of this attack—preventing lateral spread, blocking exfiltration, and detecting malicious activity early within the cloud environment.
Control: Inline IPS (Suricata)
Mitigation: Exploitable payloads for privilege escalation are detected and blocked in real time.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Detection and visibility of anomalous privilege escalation and abnormal system behavior.
Control: Zero Trust Segmentation
Mitigation: Unauthorized lateral movement is prevented or sharply constrained by microsegmentation.
Control: Egress Security & Policy Enforcement
Mitigation: C2 traffic is identified, blocked, or alerted on via egress FQDN/application filtering.
Control: Multicloud Visibility & Control
Mitigation: Anomalous exfiltration activity is detected and policy-enforced across all clouds.
Rapid detection and response to destructive behaviors minimize potential impact.
Impact at a Glance
Affected Business Functions
- Virtualization Management
- Cloud Operations
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of administrative credentials and sensitive operational data due to privilege escalation and information disclosure vulnerabilities.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy real-time inline IPS and threat detection capabilities to block exploitation of both known and unknown vulnerabilities.
- • Enforce zero trust segmentation and strict least-privilege workload-to-workload policies to stop lateral movement.
- • Centralize multicloud/network visibility and anomaly response to ensure rapid detection and remediation of malicious behaviors.
- • Implement robust egress policy enforcement, restricting outbound connections and monitoring for covert exfiltration attempts.
- • Regularly review and harden privileged access, and continuously monitor for abnormal privilege escalations within cloud workloads.



