VMware Security Updates – 13 May 2025

VMware has released security updates to fix multiple vulnerabilities across several VMware products.

The addressed vulnerabilities could allow the remote attacker with non-administrative privileges on a guest VM to manipulate certain files or perform cross-site scripting attacks on the affected product.

Sample of the addressed vulnerabilities:

VMware Aria Automation DOM-Based Cross-Site Scripting Vulnerability (CVE-2025-22249):

  • CVSS: 8.2
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: Required
  • Consequences: Cross-Site Scripting

The affected products:

  • VMware Aria Automation.
  • VMware Cloud Foundation.
  • VMware Telco Cloud Platform.
  • VMware Tools.
Vulnerabilities
  • CVE-2025-22249
  • CVE-2025-22247
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

VMware Security Update

References