EXPOSURES › CVE-2021-21985
CVE-2021-21985
CRITICAL ⌖ ON CISA KEV · EXPLOITEDVMware vCenter Server RCE due to unpatched input validation flaw
VMware vCenter Server, a default component in many DIB environments, was found to have an unpatched input validation vulnerability that enabled remote code execution. This allowed attackers to compromise systems where vCenter Server is installed, potentially leading to unauthorized access and data breaches.
Shame score — Critical remote code execution flaw in a widely used DIB system, actively exploited in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |