Back

HIGH

VMware vCenter Server authenticated command-execution vulnerability

Published May 20, 2025

Description

The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published May 20, 2025
Updated Jun 24, 2025
Reserved Apr 16, 2025
CISA Vulnrichment
Updated May 20, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a