Junglewise Threat Intelligence

CVE-2021-22005: VMware vCenter Server File Upload Vulnerability

CVE-2021-22005 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: VMware Cloud Foundation. Vendors: VMware.

Executive brief

VMware vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A remote attacker with network access to port 443 can exploit this to execute arbitrary code by uploading a specially crafted file.

Affected products

  • VMware vCenter Server 6.5, 6.7, 7.0
  • VMware Cloud Foundation 3.0 to 5.0 (exclusive)

Timeline

  • 2021-09-23: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild