cbcvebase.
CVE-2025-41250
published 2025-09-29

CVE-2025-41250: VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create…

high8.5CVSS 3.1
AVNACLPRLUINSCCNIHAL
VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.

Affected

8 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation
vmwarecloud_foundation>= 5.x < 5.2.25.2.2
vmwarecloud_foundation>= 9.x.x.x < 9.0.1.09.0.1.0
vmwaretelco_cloud_infrastructure
vmwaretelco_cloud_platform
vmwarevcenter>= 7.0 < 7.0 U3w7.0 U3w
vmwarevcenter>= 8.0 < 8.0 U3g8.0 U3g
vmwarevsphere_foundation>= 9.x.x.x < 9.0.1.09.0.1.0