Executive brief
The VMware vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. An unauthenticated attacker with network access to port 443 can exploit this to execute commands with unrestricted privileges on the underlying operating system.
Affected products
- VMware vCenter Server 7.x before 7.0 U1c, 6.7 before 6.7 U3l, 6.5 before 6.5 U3n
- VMware Cloud Foundation 4.x before 4.2, 3.x before 3.10.1.2
Timeline
- 2021-11-03: disclosed
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog.