PT-2025-39851 · Vmware · Vmware Vcenter

CVE-2025-41250

·

Published

2025-09-29

·

Updated

2025-12-23

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions VMware vCenter (affected versions not specified)
Description VMware vCenter contains an SMTP header injection vulnerability. An attacker with non-administrative privileges on vCenter, who has permission to create scheduled tasks, may be able to manipulate the notification emails sent for scheduled tasks. This allows for the crafting of malicious email notifications.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12560
CVE-2025-41250

Affected Products

Vmware Vcenter