CVE-2025-41225

The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) vCenter Server presenta una vulnerabilidad de ejecución de comandos autenticados. Un agente malicioso con privilegios para crear o modificar alarmas y ejecutar scripts podría aprovechar esta vulnerabilidad para ejecutar comandos arbitrarios en vCenter Server.

20 May 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-20 15:16

Updated : 2026-04-15 00:35


NVD link : CVE-2025-41225

Mitre link : CVE-2025-41225

CVE.ORG link : CVE-2025-41225


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')