EXPOSURES › CVE-2021-39144
CVE-2021-39144
HIGH ⌖ ON CISA KEV · EXPLOITEDXStream RCE in VMware Cloud Foundation exploited before patch
XStream's VMware Cloud Foundation product had a remote code execution vulnerability actively exploited in the wild, impacting multiple products.
Shame score — Active exploitation of a known vulnerability with no patch available, leading to potential command execution on servers.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation.