Skip to content
COOEY

EXPOSURES › CVE-2021-22005

CVE-2021-22005

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-22005 ↗
⌖ EXPLOITED IN THE WILD SHAME 80/100 ransomwareexploited-in-wild

VMware's vCenter Server had a file upload vulnerability actively exploited by ransomware actors, allowing code execution over port 443.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
VMware faced severe fallout due to actively exploited zero-day vulnerabilities in ESXi, leading to ransomware attacks and urgent patch releases under Broadcom ownership.
The Hacker News ↗ severe-fallout -0.80
The Hacker News reports on actively exploited VMware security flaws, with Broadcom releasing urgent patches.
"Broadcom has released security updates to address three actively exploited security flaws in VMware ESXi, Workstation, and Fusion products that could lead to code execution and information disclosure."
cybersecuritynews.com ↗ severe-fallout -0.80
CISA warns of active exploitation of VMware ESXi zero-day vulnerabilities in ransomware attacks, highlighting severe fallout.
"CISA recently confirmed that ransomware groups are actively exploiting CVE-2025-22225, a high-severity VMware ESXi sandbox escape vulnerability."
www.huntress.com ↗ severe-fallout -0.70
Huntress reports on active exploitation of ESXi vulnerabilities in the wild, indicating severe security failures.
"ESXi Exploitation in the Wild"
cooey ↗ severe-fallout -0.50
NVD confirms the severity of the file upload vulnerability in VMware vCenter Server, allowing code execution via port 443.
"VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code."
NIST ↗ severe-fallout +0.00
NVD page provides no direct sentiment toward VMware, only listing the vulnerability database.
NVD ↗ severe-fallout +0.00
NVD page provides no direct sentiment toward VMware, only listing the vulnerability database.
NVD ↗ severe-fallout +0.00
NVD page provides no direct sentiment toward VMware, only listing the vulnerability database.
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized