Junglewise Threat Intelligence

CVE-2021-21985: VMware vCenter Server Improper Input Validation Vulnerability

CVE-2021-21985 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: VMware.

Executive brief

The VMware vSphere Client (HTML5) contains a remote code execution vulnerability due to improper input validation in the Virtual SAN Health Check plug-in. A malicious actor with network access to port 443 can exploit this to execute commands with unrestricted privileges on the underlying operating system hosting vCenter Server.

Affected products

  • VMware vCenter Server
  • VMware vSphere Client (HTML5)

Timeline

  • 2021-11-03: disclosed
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-17: other: CISA KEV due date for remediation
  • 2021-07-13: other: Exploit code published on Packet Storm