VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.
References
Configurations
No configuration.
History
29 Sep 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-29 18:15
Updated : 2025-09-29 19:34
NVD link : CVE-2025-41250
Mitre link : CVE-2025-41250
CVE.ORG link : CVE-2025-41250
JSON object : View
Products Affected
No product.
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')