Input validation error in vCenter Server - CVE-2025-41250
Published: September 30, 2025
Vulnerability identifier: #VU116193
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N]
CVE-ID: CVE-2025-41250
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform phishing attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote user who has permission to create scheduled tasks can inject arbitrary SMTP headers and manipulate the notification emails sent for scheduled tasks.
Affected software
vCenter Server
IBM Cloud Pak System
IBM Cloud Pak System
How to mitigate CVE-2025-41250
Install updates from vendor's website.
vCenter Server - addressed in versions 7.0 U3w, 8.0 U3g
IBM Cloud Pak System - update to 2.3.6.1
IBM Cloud Pak System - update to 2.3.6.1