PT-2025-39851 · Vmware · Vmware Vcenter

Published

2025-09-29

·

Updated

2025-12-23

·

CVE-2025-41250

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions VMware vCenter (affected versions not specified)
Description VMware vCenter contains an SMTP header injection vulnerability. An attacker with non-administrative privileges on vCenter, who has permission to create scheduled tasks, may be able to manipulate the notification emails sent for scheduled tasks. This allows for the crafting of malicious email notifications.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-12560
CVE-2025-41250

Affected Products

Vmware Vcenter