Executive brief
VMware vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A remote attacker with network access to port 443 can exploit this to execute arbitrary code by uploading a specially crafted file.
Affected products
- VMware vCenter Server 6.5, 6.7, 7.0
- VMware Cloud Foundation 3.0 to 5.0 (exclusive)
Timeline
- 2021-09-23: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild