CVE-2021-21972KEV Β· OVERDUECWE-22path-traversal

VMware vCenter Server Remote Code Execution Vulnerability

Critical Β· published February 24, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 9.8. It is confirmed in active exploitation. It sits in the 100.0th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
9.8
EPSS
100%
Percentile
100.0
In the wild
Confirmed
What it is

🚨 A single connection to port 443 could let an attacker execute commands on your vCenter Server! πŸ”₯ Imagine a tech-savvy burglar who finds an unlocked backdoor to your digital vault, slipping in and taking control of everything without anyone noticing. That’s what this vulnerability is like, allowing malicious actors unrestricted access to your system. If exploited, this vulnerability could lead to complete domination of your vCenter Server! An attacker could run any command, accessing sensitive data, altering configurations, or even stopping critical services, all while leaving you blind to their actions. This is absolutely devastating for any organization relying on VMware infrastructure.

Put simply

Imagine a tech-savvy burglar who finds an unlocked backdoor to your digital vault, slipping in and taking control of everything without anyone noticing. That’s what this vulnerability is like, allowing malicious actors unrestricted access to your system. This vulnerability in the vSphere Client (HTML5) allows remote code execution via a vCenter Server plugin, enabling attackers with network access to exploit the system with no authentication hurdle.

What to do

If exploited, this vulnerability could lead to complete domination of your vCenter Server! An attacker could run any command, accessing sensitive data, altering configurations, or even stopping critical services, all while leaving you blind to their actions. This is absolutely devastating for any organization relying on VMware infrastructure. To shield your systems, patch your VMware vCenter Server to versions 7.0 U1c or later, 6.7 U3l, or 6.5 U3n immediately. For VMware Cloud Foundation, upgrade to 4.2 or 3.10.1.2. Don’t forget to audit your network to ensure that no unauthorized access is lingering! You’ve got this! Follow these steps, and your defenses will be back on track in no time. πŸ›‘οΈ

The record
Technical detail
CVSS v3.1
9.8 Β· CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.99865 Β· 100.0th percentile
Weakness
CWE-22 Β· Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Published
2021-02-24T22:15Z
KEV added
2021-11-03 Β· due 2021-11-17
Affected products (43)
ProductVersionsFixed in
vmware/cloud_foundationβ‰₯ 3.0, < 3.10.1.23.10.1.2
vmware/cloud_foundationβ‰₯ 4.0, < 4.24.2
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
vmware/vcenter_serverall versionsβ€”
References (9)
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV β€” remediate by Nov 17
    kev
  • 24 FEB 16:42Z
    The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin
    cvelistv5