CVE-2021-21972
Last modified
CVE-2021-21972 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.52% chance of exploitation in the next 30 days.
Description
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Cloud Foundation | >= 3.0, < 3.10.1.2 |
| Vmware | Cloud Foundation | >= 4.0, < 4.2 |
| Vmware | Vcenter Server | 6.5 |
| Vmware | Vcenter Server | 6.7 |
| Vmware | Vcenter Server | 7.0 |
References
- http://packetstormsecurity.com/files/161590/VMware-vCenter-Server-7.0-Arbitrary-File-Upload.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/161695/VMware-vCenter-Server-File-Upload-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/163268/VMware-vCenter-6.5-6.7-7.0-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/161590/VMware-vCenter-Server-7.0-Arbitrary-File-Upload.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/161695/VMware-vCenter-Server-File-Upload-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/163268/VMware-vCenter-6.5-6.7-7.0-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21972US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-21972?
How severe is CVE-2021-21972?
How do I fix CVE-2021-21972?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-21967An out-of-bounds write vulnerability exists in the OTA updat…5.9
- CVE-2021-21968A file write vulnerability exists in the OTA update task fun…8.3
- CVE-2021-21969An out-of-bounds write vulnerability exists in the HandleSea…8.1
- CVE-2021-2197Vulnerability in the Oracle iStore product of Oracle E-Busin…8.2
- CVE-2021-21970An out-of-bounds write vulnerability exists in the HandleSea…8.1
- CVE-2021-21971An out-of-bounds write vulnerability exists in the URL_decod…5.9
- CVE-2021-21973The vSphere Client (HTML5) contains an SSRF (Server Side Req…5.3
- CVE-2021-21974OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 …8.8
- CVE-2021-21975Server Side Request Forgery in vRealize Operations Manager A…7.5
- CVE-2021-21976vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8…7.2
- CVE-2021-21978VMware View Planner 4.x prior to 4.6 Security Patch 1 contai…9.8
- CVE-2021-21979In Bitnami Containers, all Laravel container versions prior …7.3
Are you affected by CVE-2021-21972?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
