VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 29 Sep 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX. | |
Title | Improper authorisation vulnerability | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2025-09-29T15:57:58.438Z
Reserved: 2025-04-16T09:30:25.625Z
Link: CVE-2025-41246

No data.

Status : Awaiting Analysis
Published: 2025-09-29T16:15:37.890
Modified: 2025-09-29T19:34:10.030
Link: CVE-2025-41246

No data.

No data.