The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade vmware/open-vm-tools
to version 12.5.4 or higher.
Affected versions of this package are vulnerable to Information Exposure via the service discovery process. An attacker can gain root-level privileges by leveraging access to a virtual machine where the relevant tools are installed and managed.
Note: The vulnerability was reported for systems managed by Aria Operations and was determined by Broadcom as applicable for open-vm-tools.
To detect CVE-2025-41244’s exploitation, organizations should look for uncommon child processes. In environments without monitoring, analysis of lingering metrics collector scripts and outputs in legacy credential-based mode should confirm the exploitation.