peter bassill · operator
$ cve CVE-2021-21972 JSON

CVE-2021-21972 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2021-11-17.

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.87% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2021-11-17
Public exploityes
Published2021-02-24
Last modified2026-08-12

CISA KEV

NameVMware vCenter Server Remote Code Execution Vulnerability
Added2021-11-03
Due2021-11-17
Vendor / productVMware / vCenter Server
Ransomware useknown

Affected (2)

VendorProduct
vmwarecloud foundation
vmwarevcenter server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD