CVE-2025-41250

Publication date

2025-09-29 17:44:27

Family

vmware

State

PUBLISHED

Description

VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.