PT-2025-39851 · Vmware · Vmware Vcenter
Published
2025-09-29
·
Updated
2025-12-23
·
CVE-2025-41250
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
VMware vCenter (affected versions not specified)
Description
VMware vCenter contains an SMTP header injection vulnerability. An attacker with non-administrative privileges on vCenter, who has permission to create scheduled tasks, may be able to manipulate the notification emails sent for scheduled tasks. This allows for the crafting of malicious email notifications.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Vcenter