CVE-2025-41225Patch

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-23: 1Patch / Workaround · 2026-05-23: 105-23
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Dell issues DSA-2025-434 and DSA-2025-435 for PowerFlex Rack and Appliance, fixing dozens of CVEs incl. CVE-2025-41225, CVE-2025-20191, CVE-2025-26482 in PowerEdge and VMware. https://threatcluster.io/cluster/dell-powerflex-security-updates-address-multiple-vulnerabili-e2e483d5

    Post summary

    Dell has released new DSAs (DSA‑2025‑434 and DSA‑2025‑435) to patch several CVEs affecting PowerFlex Rack and Appliance, PowerEdge, and VMware products.

    00000697
    279 followersView on X

Explore more