Junglewise Threat Intelligence

CVE-2021-21972: VMware vCenter Server Remote Code Execution Vulnerability

CVE-2021-21972 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: VMware Cloud Foundation. Vendors: VMware.

Executive brief

The VMware vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. An unauthenticated attacker with network access to port 443 can exploit this to execute commands with unrestricted privileges on the underlying operating system.

Affected products

  • VMware vCenter Server 7.x before 7.0 U1c, 6.7 before 6.7 U3l, 6.5 before 6.5 U3n
  • VMware Cloud Foundation 4.x before 4.2, 3.x before 3.10.1.2

Timeline

  • 2021-11-03: disclosed
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog.