Database/Control plane, storage & DevOps
VMware vCenter (SMTP header injection via scheduled tasks): A non-administrative user with scheduled-task permissions
CVE-2025-41250Control plane, storage & DevOpscurated
Impact
A non-administrative user with scheduled-task permissions manipulates vCenter notification emails - useful for phishing operators with mail that genuinely originates from vCenter.
Who can reach it
Authenticated low-privilege vCenter user able to create scheduled tasks.
What to do
Apply the Broadcom fix per advisory 36150. vCenter patch; low urgency relative to the RCE issues but it enables convincing internal phishing.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.