CVE-2025-41244
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
4 articles
EPSS Score
Source: FIRST.org · 2026-05-24
0.59%
probability
This CVE has a 0.59% probability
of being exploited in the next 30 days.
0%
Top 69.5th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Exploits & PoC
NULL200OK/CVE-2025-41244
CVE-2025-41244 is a critical local privilege escalation vulnerability in VMware Aria Operations and VMware Tools
2
1 repo — triés par ⭐
Rechercher sur GitHub ↗
Chinese hackers exploiting VMware zero-day since October 2024
BleepingComputer
Sep 30, 2025
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable-Research
May 27, 2026
CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks
TheHackerNews
Oct 31, 2025
Signal Intelligence
Confidence
92%
EPSS
0.59%
Mentions
4
Last Seen
May 27, 2026
CNA Information
Analyst Note
CVE-2025-41244 shows clear zero-day characteristics: exploitation in the wild by Chinese threat actors documented since October 2024 (preceding the September 29, 2025 publication date), and CISA KEV listing confirmed per article excerpt indicating active exploitation triggered the KEV addition. The timing establishes exploitation preceded public awareness.
Threat Actors 27
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
APT27
apt_group
Information theft and espionage
🇨🇳 CN
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
SCATTERED SPIDER
apt_group
Financial crime
🇺🇸 US
LAPSUS
apt_group
🇬🇧 GB
Ice Fog
apt_group
Information theft and espionage
🇨🇳 CN
Gamaredon Group
apt_group
Information theft and espionage
🇷🇺 RU
HAZY TIGER
apt_group
Information theft and espionage
🇮🇳 IN
Infy
apt_group
Information theft and espionage
🇮🇷 IR
Group 27
apt_group
Information theft and espionage
🇨🇳 CN
ArcaneDoor
apt_group
🇨🇳 CN
Pirate Panda
apt_group
Information theft and espionage
🇨🇳 CN
LUNAR SPIDER
apt_group
🇷🇺 RU
UNC5174
apt_group
🇨🇳 CN
Returned Libra
apt_group
🇨🇳 CN
UNC3886
apt_group
Information theft and espionage
🇨🇳 CN
Crimson Collective
apt_group
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
GOFFEE
apt_group
🇷🇺 RU
Red October
apt_group
🇷🇺 RU
COOKIE SPIDER
apt_group
🇷🇺 RU
Operation Digital Eye
apt_group
Information theft and espionage
🇨🇳 CN
TRAVELING SPIDER
apt_group
Financial gain
🇷🇺 RU
Mana Team
apt_group
🇨🇳 CN
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Chaya_004
apt_group
🇨🇳 CN
Triage Info
Decided atMar 05, 2026