Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-41244-PoC — VMware Aria Operations < 4.18.5 & VMware Tools - Local Privilege Escalation | Kitploit
Tools/GitHubGitHub/haspiranti/cve-2025-41244-poc
Privilege EscalationVulnerability AnalysisExploitationPenetration TestingRed Teaming
GitHubhaspiranti/cve-2025-41244-poc

CVE-2025-41244-PoC

VMware Aria Operations < 4.18.5 & VMware Tools - Local Privilege Escalation

View Repository
111 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-41244 PoC

VMware Aria Operations < 4.18.5 & VMware Tools - Local Privilege Escalation

Background

Please read the article listed in references to get a more comprehensive and verbose explanation of the vulnerability.

TL;DR

A shell script within VMware Tools named get-versions.sh uses a broad-matching regex pattern (\S) to identify running processes with listening sockets. On matching processes, it executes the process with the respective version flag (-v, --version, etc.) to retrieve the running version of the service.

Excerpt from get-versions.sh (lines 18-26):

root@kitploit:~
get_version() {
  PATTERN=$1
  VERSION_OPTION=$2
  for p in $space_separated_pids
  do
    COMMAND=$(get_command_line $p | grep -Eo "$PATTERN")
    [ ! -z "$COMMAND" ] && echo VERSIONSTART "$p" "$("${COMMAND%%[[:space:]]*}" $VERSION_OPTION 2>&1)" VERSIONEND
  done
}

Excerpt from get-versions.sh (lines 119-124):

root@kitploit:~
get_version "/\S+/(httpd-prefork|httpd|httpd2-prefork)($|\s)" -v
get_version "/usr/(bin|sbin)/apache\S*" -v
get_version "/\S+/mysqld($|\s)" -V
get_version "\.?/\S*nginx($|\s)" -v
get_version "/\S+/srm/bin/vmware-dr($|\s)" --version
get_version "/\S+/dataserver($|\s)" -v

Theory

The top line /\S+/httpd($|\s) is designed to match on the proper installation path, such as /usr/bin/httpd. However, if an unprivileged user creates a script in /tmp/httpd, a globally writable directory, and runs the process, as long as it has a listening socket (on any interface - even localhost), it will get executed in an elevated context by the VMware Tools script - achieving local privilege escalation. This could enable a malicious user to execute a reverse shell, create a root user, or ultimately any elevated action they choose.

Proof of Concept

A golang script is executed to create a listening socket. When the get-versions.sh script matches the regex expression of /tmp/[SERVICE], it will run the script in an elevated context. When the script is ran in an elevated context, instead of creating a listening socket, it will execute an arbitrary command (e.g., /bin/bash -i), obtaining privilege escalation.

References

https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/

Download Tool