Skip to content
COOEY

FAIL › dossier

vCenter Server

PRODUCT

· dossier confidence 20%

VMware vCenter Server, a critical component in managing virtual infrastructure, has faced multiple security vulnerabilities. These vulnerabilities have been exploited by attackers, leading to unauthorized access and manipulation of the virtual environment. Proactive patching and rigorous security practices are essential to mitigate these risks.

PROFILE
CategoryvirtualizationWhat they doVMware vCenter Server is a centralized management platform that allows users to provision, configure, and manage virtual infrastructure across the organization. Websitehttps://www.vmware.com/ ↗
SECURITY POSTURE

VMware vCenter Server has been identified with multiple security vulnerabilities, indicating a potential for unauthorized access and manipulation of the virtual infrastructure.

Notable failures
  • CVE-2021-21985: VMware vCenter Server RCE due to unpatched input validation flaw
  • CVE-2021-22005: VMware's vCenter Server had a file upload vulnerability actively exploited by ransomware actors
  • CVE-2021-21972: VMware vCenter Server RCE due to unpatched plugin exploited in wild
  • CVE-2024-34048: VMware vCenter Server contains an out-of-bounds write vulnerability in the DCERPC protocol
  • CVE-2024-38813: VMware vCenter contains an improper check for dropped privileges vulnerability
  • CVE-2024-38812: VMware vCenter Server contains a heap-based buffer overflow vulnerability in the DCERPC protocol
  • CVE-2024-07718: VMware vCenter Server contains an incorrect default file permissions vulnerability
  • CVE-2022-22948: VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service
  • CVE-2021-22017: Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization
Patterns: Repeated unpatched edge-device RCEs; File upload vulnerabilities leading to code execution; Buffer overflow vulnerabilities in the DCERPC protocol; Improper privilege checks leading to information disclosure; Incorrect default file permissions leading to unauthorized access
FAILURE HISTORY · 11
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2021-21985 critical VMware vCenter Server RCE due to unpatched input validation flaw
2024-11-20 CVE-2024-38813 high VMware vCenter Server allows remote privilege escalation to root via a dropped privileges check bypass, enabling attackers to gain full control of the system.
2024-01-22 CVE-2023-34048 high VMware vCenter Server was exploited in the wild via CVE-2023-34048, enabling remote code execution through an out-of-bounds write in the DCERPC protocol.
2021-11-03 CVE-2020-3952 high An unpatched directory traversal flaw in VMware vCenter's Syslog server allowed unauthenticated attackers to gain persistent remote access via reverse SSH backdoors.
2021-11-03 CVE-2021-22005 critical VMware's vCenter Server had a file upload vulnerability actively exploited by ransomware actors, allowing code execution over port 443.
2022-01-10 CVE-2021-22017 high Attackers exploited a directory-traversal flaw in VMware vCenter's Syslog server to gain persistent remote access.
2021-11-03 CVE-2021-21972 critical VMware vCenter Server RCE due to unpatched plugin exploited in wild
2024-11-20 CVE-2024-38812 high VMware vCenter Server exploited via heap-based buffer overflow enabling remote code execution.
2024-07-17 CVE-2022-22948 high VMware vCenter Server shipped with incorrect default file permissions enabling remote privileged attackers to access sensitive data.
2021-05-26 CVE-2021-21985 critical CVE-2021-21985: The vSphere Client (HTML5) contains a remote code execution vulnerability due to
2021-02-24 CVE-2021-21972 critical CVE-2021-21972: The vSphere Client (HTML5) contains a remote code execution vulnerability in a v
Open questions: How has VMware addressed these vulnerabilities? · What is the current posture of vCenter Server in terms of security?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-24 03:44:33.304184+00:00