CVE-2025-41250: Header injection vulnerability
VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41250?
CVE-2025-41250 has a moderate severity rating due to the potential exploitation by a non-administrative user to manipulate email notifications.
How do I fix CVE-2025-41250?
To fix CVE-2025-41250, update VMware vCenter to the latest version where the vulnerability is patched.
Who can exploit CVE-2025-41250?
CVE-2025-41250 can be exploited by a malicious actor with non-administrative privileges who has permission to create scheduled tasks in VMware vCenter.
What impact does CVE-2025-41250 have on VMware vCenter?
CVE-2025-41250 allows an attacker to manipulate SMTP headers, potentially leading to phishing or social engineering attacks through altered notification emails.
How can I mitigate the risk of CVE-2025-41250?
To mitigate the risk of CVE-2025-41250, limit permissions for non-administrative users and regularly monitor scheduled tasks in VMware vCenter.