CVE-2025-41225
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
20/05/2025
Last modified:
21/05/2025
Description
The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH