Critical Β· published February 24, 2021
CVSS calls it critical at 9.8. It is confirmed in active exploitation. It sits in the 100.0th percentile for exploit probability.
π¨ A single connection to port 443 could let an attacker execute commands on your vCenter Server! π₯ Imagine a tech-savvy burglar who finds an unlocked backdoor to your digital vault, slipping in and taking control of everything without anyone noticing. Thatβs what this vulnerability is like, allowing malicious actors unrestricted access to your system. If exploited, this vulnerability could lead to complete domination of your vCenter Server! An attacker could run any command, accessing sensitive data, altering configurations, or even stopping critical services, all while leaving you blind to their actions. This is absolutely devastating for any organization relying on VMware infrastructure.
Imagine a tech-savvy burglar who finds an unlocked backdoor to your digital vault, slipping in and taking control of everything without anyone noticing. Thatβs what this vulnerability is like, allowing malicious actors unrestricted access to your system. This vulnerability in the vSphere Client (HTML5) allows remote code execution via a vCenter Server plugin, enabling attackers with network access to exploit the system with no authentication hurdle.
If exploited, this vulnerability could lead to complete domination of your vCenter Server! An attacker could run any command, accessing sensitive data, altering configurations, or even stopping critical services, all while leaving you blind to their actions. This is absolutely devastating for any organization relying on VMware infrastructure. To shield your systems, patch your VMware vCenter Server to versions 7.0 U1c or later, 6.7 U3l, or 6.5 U3n immediately. For VMware Cloud Foundation, upgrade to 4.2 or 3.10.1.2. Donβt forget to audit your network to ensure that no unauthorized access is lingering! Youβve got this! Follow these steps, and your defenses will be back on track in no time. π‘οΈ
| Product | Versions | Fixed in |
|---|---|---|
| vmware/cloud_foundation | β₯ 3.0, < 3.10.1.2 | 3.10.1.2 |
| vmware/cloud_foundation | β₯ 4.0, < 4.2 | 4.2 |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |
| vmware/vcenter_server | all versions | β |