CVE-2021-21972: VMware vCenter Server Remote Code Execution Vulnerability.
VMware vCenter Server Remote Code Execution Vulnerability. VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system.
- CISA KEV-listed (remediation due 2021-11-17)
- used in ransomware campaigns
- EPSS 93.8% (99.9% percentile)