GPU VulnDB

Database/Control plane, storage & DevOps

VMware vCenter Server (authenticated command execution via alarms): A user with permission to create or modify alarms

CVE-2025-41225Control plane, storage & DevOpscurated

Impact

A user with permission to create or modify alarms and run script actions executes arbitrary commands on vCenter. The alarm/script-action feature is a legitimate automation path that doubles as a privilege-escalation route to root on the management server.

Who can reach it

Authenticated vCenter user holding alarm-management privileges - a role commonly granted to monitoring integrations.

What to do

Apply the Broadcom fix per advisory 25717. Also audit which service accounts hold alarm/script-action rights; most monitoring integrations do not need them.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.