CVE-2021-21972
VMware vCenter Server Remote Code Execution Vulnerability
CVSS
9.8
Critical
EPSS
99.9%
p100
KEV
YES
Nov 3, 2021
Exploit Today
80
0-100
Published: Feb 24, 2021 · Last modified: Aug 12, 2026 · CWE-22
Product
VMware / vCenter Server
Vulnerability
VMware vCenter Server Remote Code Execution Vulnerability
Added to KEV
Nov 3, 2021
Remediate by
Nov 17, 2021
Known ransomware use
Yes
Summary description
VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system.
Required action
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2021-21972
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
- packetstormsecurity.comhttp://packetstormsecurity.com/files/161590/VMware-vCenter-Server-7.0-Arbitrary-File-Upload.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/161695/VMware-vCenter-Server-File-Upload-Remote-Code-Execution.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/163268/VMware-vCenter-6.5-6.7-7.0-Remote-Code-Execution.html
- www.vmware.comhttps://www.vmware.com/security/advisories/VMSA-2021-0002.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/161590/VMware-vCenter-Server-7.0-Arbitrary-File-Upload.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/161695/VMware-vCenter-Server-File-Upload-Remote-Code-Execution.html
- packetstormsecurity.comhttp://packetstormsecurity.com/files/163268/VMware-vCenter-6.5-6.7-7.0-Remote-Code-Execution.html
- www.vmware.comhttps://www.vmware.com/security/advisories/VMSA-2021-0002.html
- www.cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21972