Executive brief
The VMware vSphere Client (HTML5) contains a remote code execution vulnerability due to improper input validation in the Virtual SAN Health Check plug-in. A malicious actor with network access to port 443 can exploit this to execute commands with unrestricted privileges on the underlying operating system hosting vCenter Server.
Affected products
- VMware vCenter Server
- VMware vSphere Client (HTML5)
Timeline
- 2021-11-03: disclosed
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-17: other: CISA KEV due date for remediation
- 2021-07-13: other: Exploit code published on Packet Storm