CVE-2025-41250

HIGH

VMware vCenter 8.0-8.0 U3g, 7.0-7.0 U3w - SMTP Header Injection via Scheduled Task Notifications

Title source: llm
STIX 2.1

Description

VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.

Scores

CVSS v3 8.5
EPSS 0.0008
EPSS Percentile 22.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (8)
VMware/Cloud Foundation 4.5.x
VMware/Cloud Foundation 5.x - 5.2.2
VMware/Cloud Foundation 9.x.x.x - 9.0.1.0
VMware/Telco Cloud Infrastructure 3.x, 2.x
VMware/Telco Cloud Platform 5.x, 4.x, 3.x, 2.x
VMware/vCenter 7.0 - 7.0 U3w
VMware/vCenter 8.0 - 8.0 U3g
VMware/vSphere Foundation 9.x.x.x - 9.0.1.0
Published Sep 29, 2025
Tracked Since Feb 18, 2026