Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

SMTP Header Injection in VMware vCenter Scheduled Task Notifications

IdentifiersCVE-2025-41250CWE-77· Improper Neutralization of Special…

CVE-2025-41250 is a high-severity SMTP header injection vulnerability in VMware vCenter Server affecting the scheduled task email notification mechanism. According to the provided content, vCenter incorporates user-controlled input from scheduled task-related fields into outbound email headers without sufficient sanitization. An authenticated attacker with non-administrative privileges who has permission to create or modify scheduled tasks can inject carriage return/line feed (CRLF) sequences into relevant fields such as a task name or description, causing additional SMTP headers to be inserted or existing headers to be altered in notification emails generated by vCenter. This enables manipulation of the structure and content of scheduled task notification emails.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an attacker to tamper with vCenter-generated notification emails for scheduled tasks. The provided content specifically states this can be used to add BCC recipients and alter the subject line, which can result in unauthorized disclosure of notification content, phishing opportunities, redirection of sensitive communications, and support for further internal compromise or lateral movement in environments that rely on vCenter email notifications for operational workflows.

Mitigation

If you can’t patch tonight, do this now.

The provided content states that no workaround is available. Until patching is completed, restrict scheduled task creation and modification privileges to only trusted administrators or service accounts, review and minimize non-administrative permissions in vCenter, and implement monitoring or mail security controls to detect anomalous or manipulated SMTP headers in vCenter-generated notification emails.

Remediation

Patch, then assume compromise.

Apply Broadcom/VMware fixes referenced in VMSA-2025-0016. The provided content identifies fixed releases for affected vCenter deployments including VMware vCenter 8.0 U3g, VMware vCenter 7.0 U3w, VMware Cloud Foundation/vSphere Foundation 9.0.1.0, VMware Cloud Foundation 5.2.2, and applicable Telco platform fixes or KB guidance. Review the vendor advisory response matrices and upgrade all affected vCenter-related deployments to the appropriate fixed version.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
BroadcomVcenterapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity6

Community discussion across Reddit, Mastodon, and other social sources.