The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.
References
Configurations
No configuration.
History
20 May 2025, 15:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-20 15:16
Updated : 2025-05-21 20:25
NVD link : CVE-2025-41225
Mitre link : CVE-2025-41225
CVE.ORG link : CVE-2025-41225
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')