CVE-2025-41225

Published May 20, 2025

Last updated 2 months ago

Overview

Description
The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.
Source
security@vmware.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
6
Exploitability score
2
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security@vmware.com
CWE-78

Social media

Hype score
Not currently trending
  1. Actively exploited CVE : CVE-2025-41225

    @transilienceai

    3 Jun 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. Actively exploited CVE : CVE-2025-41225

    @transilienceai

    30 May 2025

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. CVE-2025-41225 (CVSS:8.8, HIGH) is Awaiting Analysis. The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to creat..https://t.co/p8DiRniajH #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    25 May 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨Broadcom’s VMware has disclosed seven vulnerabilities in various VMware products. - CVE-2025-41225: Authenticated RCE via alarm scripts in vCenter Server that allows arbitrary command execution with alarm privileges https://t.co/FviK2nRyds

    @BlackpointUS

    20 May 2025

    80 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. CVE-2025-41225 VMware vCenter Server Authenticated Command Execution Vulnerability https://t.co/pmGNEQIRQA

    @VulmonFeeds

    20 May 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. VMwareが複数製品における複数脆弱性を修正。ESXi, vCenter Server, Workstation Pro, Fusionを影響範囲に含む。該当脆弱性はCVE-2025-41225~41228。最も深刻なCVE-2025-41225は特権を持つ攻撃者がvCenter Serverで任意のコマンドを実行

    @__kokumoto

    20 May 2025

    783 Impressions

    3 Retweets

    8 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  7. VMSA-2025-0010 : VMware ESXi, vCenter Server, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2025-41225, CVE-2025-41226, CVE-2025-41227, CVE-2025-41228) https://t.co/poCYHIkllD

    @andersonc0d3

    20 May 2025

    261 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. ⚠️Múltiples vulnerabilidades en los productos VMware ❗CVE-2025-41225 ❗CVE-2025-41226 ➡️Más info: https://t.co/mzC9wmJmyQ https://t.co/Vh7CwyVyMj

    @CERTpy

    20 May 2025

    166 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes