VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX.
Metrics
Affected Vendors & Products
References
History
Tue, 30 Sep 2025 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Microsoft
Microsoft windows Vmware Vmware tools |
|
Vendors & Products |
Microsoft
Microsoft windows Vmware Vmware tools |
Mon, 29 Sep 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX. | |
Title | Improper authorisation vulnerability | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2025-09-30T03:55:11.488Z
Reserved: 2025-04-16T09:30:25.625Z
Link: CVE-2025-41246

No data.

Status : Awaiting Analysis
Published: 2025-09-29T16:15:37.890
Modified: 2025-09-29T19:34:10.030
Link: CVE-2025-41246

No data.