LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-21985: VMware vCenter Server Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
CVSS 9.8 · Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
9.8
CVSS score
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-21985 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

CVE-2021-21985 is an improper input validation vulnerability in VMware vCenter Server that affects the Virtual SAN Health Check plug-in in the vSphere Client. The plug-in is enabled by default, and successful abuse can lead to remote code execution on the vCenter Server. Because vCenter is a central management plane for virtual infrastructure, compromise can give an attacker broad reach across hosts, datastores, and workloads. Public reporting associates this issue with known ransomware use, so timely response matters.

Defenders should treat any unpatched vCenter instance as high priority, confirm exact impact and fixed builds against the vendor advisory, and follow CISA’s required action to apply updates per vendor instructions.

How it works

The weakness is classified under improper input validation (CWE-20), with related concerns around unsafe reflection (CWE-470) and server-side request forgery (CWE-918). In plain terms, the Virtual SAN Health Check plug-in does not adequately validate input it receives. An attacker who can reach the affected interface can supply crafted input that the plug-in processes unsafely, resulting in remote code execution in the context of the vCenter Server process.

Exact request format, authentication requirements, and exploit mechanics are not detailed here; those specifics must be confirmed against the vendor advisory. What matters for defenders is that the plug-in is present and enabled by default in typical vCenter deployments, so network-accessible vCenter management interfaces are the primary exposure surface for this class of flaw.

Am I affected? How to find it in your systems

VMware vCenter Server is commonly deployed as the management component for vSphere environments, often as a Linux-based appliance or on Windows, and is reachable from administrator workstations, jump hosts, and sometimes broader management networks. Inventory every vCenter Server instance, including lab, DR, and secondary sites.

How to remediate

Patch first. Apply the updates VMware released for this vulnerability, following the vendor advisory and CISA’s direction to apply updates per vendor instructions. Schedule maintenance windows promptly; vCenter is sensitive infrastructure, so use tested change procedures and snapshots or backups as recommended by VMware.

If you can't patch immediately

Reduce exposure until the vendor update can be applied.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently lead to full environment compromise and data theft or encryption. If your vCenter was unpatched and reachable, assume potential misuse until you investigate: isolate affected systems if compromise is suspected, preserve logs, engage incident response, and follow your breach-notification obligations. As one additional check, you can run a free exposure scan of your email addresses against known breach datasets to see whether associated credentials or identities have appeared in prior public breaches, then force password resets and MFA where appropriate.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVMware · vCenter Server
WeaknessCWE-918
CVSS base score9.8 (Critical)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
PublishedMay 26, 2021
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useYes
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities