LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-21972: VMware vCenter Server Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-21972 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with…

CVE-2021-21972 is a remote code execution vulnerability in VMware vCenter Server. It affects a plugin used by the vSphere Client and lets an attacker who can reach the service over the network on port 443 run commands with unrestricted privileges on the underlying operating system. Because vCenter is a central management plane for virtual infrastructure, successful exploitation can give an attacker broad control of the environment. Public reporting also links this vulnerability to ransomware activity, so rapid identification and remediation matter.

How it works

The weakness is classified as CWE-23 (relative path traversal). In products of this class, insufficient validation of path or file references inside a component can allow an attacker to reach resources or functionality outside the intended scope. According to the CISA summary, the flaw resides in a vCenter Server plugin exposed through the vSphere Client. An unauthenticated attacker with network access to port 443 can abuse the vulnerable plugin path to execute operating-system commands at the highest privilege level on the host running vCenter. Exact request formats and payload details are not repeated here; defenders should obtain them only from the official vendor advisory and treat any public proof-of-concept material with caution.

Am I affected? How to find it in your systems

VMware vCenter Server is typically deployed as a dedicated appliance or Windows installation that manages ESXi hosts and virtual machines. It is commonly reachable on TCP port 443 for the web-based vSphere Client and related APIs. Inventory every vCenter instance in your environment—production, lab, and disaster-recovery sites—by consulting configuration-management databases, network scans for port 443 services identifying themselves as vCenter/vSphere, and VMware’s own management tools.

How to remediate

The primary action is to apply the security updates published by VMware for this CVE. Follow the vendor’s instructions exactly—CISA’s required action is simply “Apply updates per vendor instructions.” After patching, verify the installed build number matches the fixed release listed in the advisory. As additional hardening for this class of flaw:

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities, especially those tied to ransomware, frequently lead to data theft or encryption. If you discover evidence of exploitation or cannot rule it out, treat the vCenter host and any systems it manages as potentially compromised: isolate, preserve forensic images, rotate credentials, and follow your incident-response plan. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVMware · vCenter Server
WeaknessCWE-23
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities