Advancing Health Podcast
H-ISAC TLP White Threat Bulletin: Exploitation Confirmed for VMware Flaw CVE-2025-41244
On September 29, 2025, Broadcom issued an advisory for a local privilege escalation flaw tracked as CVE-2025-41244, affecting VMware Tools and VMware Aria Operations guest service discovery features. According to security researchers from NVISO, the company failed to disclose active exploitation of this flaw.
Cybersecurity researchers have confirmed that a sophisticated, Chinese state-sponsored threat actor identified as UNC5174 has been covertly leveraging this flaw since at least mid-October 2024.
View the detailed report below.
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:
John Riggi
National Advisor for Cybersecurity and Risk, AHA
jriggi@aha.org
(O) +1 202 626 2272
Key Resources
Related Resources
Special Bulletin
AHA Center for Health Innovation Market Scan