CVE-2025-41250

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
29/09/2025
Last modified:
29/09/2025

Description

VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.