SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-21985

VMware vCenter Server Improper Input Validation Vulnerability

KEVCRITICAL 9.8EPSS 100.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 17 November 2021). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
100.00% probability · 100th percentile
CISA KEV
Listed 3 November 2021 · due 17 November 2021 · used in ransomware campaigns
Weakness
CWE-918, CWE-20, CWE-470
Affected
vmware/vcenter server · vmware/cloud foundation
Source
security@vmware.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-21985

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.