GPU VulnDB

Database/Control plane, storage & DevOps

VMware vCenter (SMTP header injection via scheduled tasks): A non-administrative user with scheduled-task permissions

CVE-2025-41250Control plane, storage & DevOpscurated

Impact

A non-administrative user with scheduled-task permissions manipulates vCenter notification emails - useful for phishing operators with mail that genuinely originates from vCenter.

Who can reach it

Authenticated low-privilege vCenter user able to create scheduled tasks.

What to do

Apply the Broadcom fix per advisory 36150. vCenter patch; low urgency relative to the RCE issues but it enables convincing internal phishing.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.