CRITICAL

CVE-2021-21972

Vmware Cloud Foundation 2021-02-24 CVSS v3.1
CVSS
9.8
KEV

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

Summary dbcve.org

A critical remote code execution vulnerability exists in the vSphere Client (HTML5) interface of vCenter Server, specifically within a vCenter Server plugin. The flaw allows an unauthenticated attacker with network access to port 443 to execute arbitrary commands with unrestricted privileges on the underlying operating system hosting the vCenter Server.

Mitigation

Apply the vendor-supplied patches by upgrading vCenter Server to version 7.0 U1c or later (7.x), 6.7 U3l or later (6.7.x), or 6.5 U3n or later (6.5.x); alternatively, upgrade VMware Cloud Foundation to 4.2+ or 3.10.1.2+ as appropriate.

Proof of Concept

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

99.87%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE