CVE-2025-41228: VMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) Vulnerability
VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41228?
CVE-2025-41228 has been rated as a medium severity vulnerability due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2025-41228?
To fix CVE-2025-41228, ensure that you apply the latest security patches provided by VMware for ESXi and vCenter Server.
What are the impacts of CVE-2025-41228 if exploited?
If exploited, CVE-2025-41228 can allow attackers to steal session cookies or redirect users to malicious sites.
Who is affected by CVE-2025-41228?
CVE-2025-41228 affects users of VMware ESXi and VMware vCenter Server with network access to the login page.
How can I verify if my VMware is affected by CVE-2025-41228?
You can verify if your VMware installation is affected by CVE-2025-41228 by checking the version against VMware's security advisory releases.