VMware Service Discovery Suspicious Binary Execution (CVE-2025-41244)
Detects potential exploitation of CVE-2025-41244, a local privilege escalation vulnerability in VMware Tools and Aria Operations. An attacker can stage a malicious binary in a world-writable directory (e.g., /tmp) which is then executed with root privileges by the VMware service discovery mechanism when it attempts to determine the binary's version.
Sigma

