cbcvebase.
CVE-2025-41241
published 2025-07-29

CVE-2025-41241: VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for…

PriorityP417medium4.4CVSS 3.1
AVNACHPRHUINSUCNINAH
EPSS
0.27%
19.4th percentile
VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service condition.

Affected

5 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation
vmwaretelco_cloud_infrastructure
vmwaretelco_cloud_platform
vmwarevcenter>= 7.0 < 7.0 U3v7.0 U3v
vmwarevcenter>= 8.0 < 8.0 U3g8.0 U3g
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.