List
THREAT SUMMARY Broadcom has released security updates for VMware Aria Operations and VMware Tools to address multiple vulnerabilities that could enable local privilege escalation, information disclosure, and improper authorization bypass. Exploitation may allow attackers to gain elevated privileges or access sensitive information in affected VMware environments. IMPACTED PRODUCTS • VMware Aria Operations • VMware Tools
VMware has patched multiple flaws in Aria Operations & VMware Tools (VMSA-2025-0015). • CVE-2025-41244: Privilege Escalation (CVSS 7.8) • CVE-2025-41245: Info Disclosure (CVSS 4.9) • CVE-2025-41246: Improper Authorization (CVSS 7.6) No workarounds. Immediate patching required. Read more: https://nccc.gov.sl/Alerts_Advisories/
THREAT OVERVIEW SL-CSIRT warns all system administrators, organizations, and the general public about a newly disclosed critical vulnerability in the widely used sudo utility on Linux/Unix systems. The flaw, tracked as CVE-2025-32463 (CVSS 9.3), allows local attackers to execute arbitrary commands with root privileges, bypassing restrictions in the sudoers configuration. The U.S. Cybersecurity and Infrastructure