LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-22005: VMware vCenter Server File Upload Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-22005 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.

CVE-2021-22005 is a file upload vulnerability in VMware vCenter Server’s Analytics service. An attacker who can reach the service over the network on port 443 can abuse it to execute code on the system. Because vCenter is the central management plane for many VMware environments, successful exploitation can give an attacker broad control over virtual infrastructure. The flaw has been used by ransomware operators, so timely response matters.

How it works

The weakness is classified as CWE-23 (relative path traversal). In this case it appears in the Analytics service of vCenter Server. A user with network access to port 443 can upload a crafted file in a way that bypasses intended path restrictions. Once the file is placed where the service will process it, the attacker can achieve code execution on the vCenter host. Exact request formats and payload details are not required for defenders; the essential point is that unauthenticated or lightly authenticated network access to the Analytics endpoint on 443 is sufficient to trigger the issue. Confirm the precise attack surface and any authentication requirements against the vendor advisory.

Am I affected? How to find it in your systems

VMware vCenter Server is typically deployed as a virtual appliance or Windows installation that manages ESXi hosts, clusters, and related services. It commonly listens on HTTPS (port 443) and is reachable from management networks, jump hosts, or, in poorly segmented environments, broader internal or even external networks.

How to remediate

The primary action is to apply the updates published by VMware for this vulnerability, following the vendor’s instructions exactly. CISA’s required action is the same: apply updates per vendor instructions. After patching, verify the new build number and confirm the Analytics service is running the remediated code. Reboot or restart services only as directed by the advisory. Once the patch is confirmed, review accounts, roles, and any recently created or modified objects for signs of prior compromise. Harden the management plane by restricting port 443 access to authorized administrative networks only and by disabling any unused services that the advisory or VMware hardening guides identify as unnecessary.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These steps lower risk but do not eliminate it; schedule the official update as soon as possible.

If your data may have been exposed

Actively exploited vulnerabilities, especially those known to be used by ransomware groups, frequently lead to full environment compromise and data theft or encryption. If your vCenter instances were reachable on port 443 and unpatched during the period of known exploitation, assume potential exposure of credentials, virtual-machine data, and connected infrastructure. Rotate privileged credentials, review backup integrity, and investigate lateral movement. As an additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVMware · vCenter Server
WeaknessCWE-23
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities