CVE-2025-41225: VMware vCenter Server authenticated command-execution vulnerability
The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41225?
CVE-2025-41225 is classified as a high-severity vulnerability due to its potential for unauthorized command execution.
How do I fix CVE-2025-41225?
To fix CVE-2025-41225, apply the latest patches and updates provided by VMware for vCenter Server.
Who is affected by CVE-2025-41225?
CVE-2025-41225 affects VMware vCenter Server installations with authenticated users who can create or modify alarms and execute script actions.
What can an attacker do with CVE-2025-41225?
An attacker exploiting CVE-2025-41225 can run arbitrary commands on the vCenter Server, potentially compromising the system.
Is CVE-2025-41225 easy to exploit?
Exploitation of CVE-2025-41225 requires authenticated access with specific privileges, making it dependent on user permissions.