CVE-2021-21972
Description
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
Summary dbcve.org
A critical remote code execution vulnerability exists in the vSphere Client (HTML5) interface of vCenter Server, specifically within a vCenter Server plugin. The flaw allows an unauthenticated attacker with network access to port 443 to execute arbitrary commands with unrestricted privileges on the underlying operating system hosting the vCenter Server.
Mitigation
Apply the vendor-supplied patches by upgrading vCenter Server to version 7.0 U1c or later (7.x), 6.7 U3l or later (6.7.x), or 6.5 U3n or later (6.5.x); alternatively, upgrade VMware Cloud Foundation to 4.2+ or 3.10.1.2+ as appropriate.