cbcvebase.
CVE-2025-41225
published 2025-05-20

CVE-2025-41225: The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script…

high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.

Affected

5 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation
vmwaretelco_cloud_infrastructure
vmwaretelco_cloud_platform
vmwarevcenter_server>= 7.0 < 7.0 U3v7.0 U3v
vmwarevcenter_server>= 8.0 < 8.0 U3e8.0 U3e