References https://nvd.nist.gov/vuln/detail/CVE-2025-41250 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36150 https://zeropath.com/blog/cve-2025-41250-vmware-vcenter-smtp-header-injection https://www.sentinelone.com/vulnerability-database/cve-2025-41250/ https://www.tenable.com/cve/CVE-2025-41250 https://github.com/advisories/GHSA-5qfp-g44c-j8xm https://www.securityweek.com/high-severity-vulnerabilities-patched-in-vmware-aria-operations-nsx-vcenter/ https://gbhackers.com/vmware-vcenter-and-nsx-flaws/ https://cyberpress.org/vmware-vcenter-and-nsx-vulnerabilities/ https://cve.imfht.com/detail/CVE-2025-41250
Related VulnerabilitiesVMware ESXi /sdk 默认口令漏洞PoCCVE-2021-22017: vCenter Server - Improper Access ControlPoCCVE-2022-31678: VMWare Cloud Foundation NSX-V - XML External Entity (XXE)PoCCVE-2018-6961: VMware NSX SD-WAN Edge - Command Injection(CVE-2025-41252) VMware NSX未认证的用户名枚举漏洞(CVE-2025-41246) VMware Tools for Windows授权不当漏洞Vmware Spring Security 逻辑缺陷漏洞Vmware Spring Framework 逻辑缺陷漏洞CVE-2023-20888: VMware Aria Operations for Networks - Remote Code ExecutionPoCCVE-2021-21972: VMware vSphere Client (HTML5) - Remote Code ExecutionPoCCVE-2021-21973: VMware vSphere - Server-Side Request ForgeryPoCCVE-2021-21978: VMware View Planner <4.6 SP1- Remote Code ExecutionPoCCVE-2021-21985: VMware vSphere Client (HTML5) - Remote Code Execution