LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-22017: VMware vCenter Server Improper Access Control

RBRecent Breaches Vulnerability Intelligence·Jan 10, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-22017 to its Known Exploited Vulnerabilities catalog on Jan 10, 2022, with a federal patch deadline of Jan 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.

CVE-2021-22017 is an improper access control vulnerability in VMware vCenter Server, specifically involving the rhttproxy component and flawed URI normalization. It allows an attacker who can reach the affected service to abuse path handling in a way that bypasses intended access restrictions. For IT and security teams, this matters because vCenter is a central management plane for virtual infrastructure; compromise can lead to broader control of hosts, VMs, and related systems. Confirm all product and version details against the vendor advisory before acting.

How it works

The weakness is classified as CWE-23, which covers relative path traversal issues that arise from improper URI or path normalization. In this case, rhttproxy as used in vCenter Server does not correctly normalize certain URIs. An attacker who can send crafted requests to the service may be able to reach resources or perform actions outside the intended access boundaries by exploiting how paths are resolved after normalization fails.

At a high level, the abuse pattern for this class is straightforward: the attacker supplies input containing path elements that the component fails to canonicalize or restrict properly, allowing traversal or unauthorized access relative to the intended root. Exact request formats, preconditions, and impact depend on the deployment and must be confirmed against the vendor advisory; do not assume remote unauthenticated exploitation or specific outcomes without that guidance.

Am I affected? How to find it in your systems

VMware vCenter Server is typically deployed as the central management appliance or Windows-based installation that administers ESXi hosts and virtual machines in VMware environments. It often runs on dedicated management networks but may be reachable from broader administrative or jump-host segments.

To inventory:

For signs of exploitation, review web and proxy access logs associated with vCenter for unusual URI patterns that include traversal sequences or unexpected path normalization attempts, anomalous requests to management endpoints, and any unexplained authentication or authorization anomalies. Correlate with authentication logs, process creation on the vCenter host, and outbound connections. Because public detail on specific indicators is limited, treat any suspicious activity on exposed vCenter interfaces as warranting investigation and confirm detection guidance with the vendor advisory and your own baseline telemetry.

How to remediate

Patch first. Apply the updates published by VMware for vCenter Server exactly as described in the vendor advisory for CVE-2021-22017. CISA directs organizations to apply updates per vendor instructions. After patching, verify the installed build matches the fixed version and re-test access controls on the previously affected interfaces.

Beyond the patch, harden this class of system:

If you can't patch immediately

Reduce exposure until the vendor update can be applied:

These steps are compensating controls only; they do not replace the vendor patch.

If your data may have been exposed

Actively exploited management-plane vulnerabilities can lead to unauthorized access, lateral movement, and data exposure even when ransomware use is not documented for this specific CVE. If you have reason to believe an instance was reachable and unpatched during the relevant period, treat it as a potential incident: isolate, preserve logs, review for persistence or unauthorized changes, and follow your incident response process. You can also run a free exposure scan of your email addresses against known breach data sets to check whether associated credentials or personal data have appeared in prior breaches, then force password resets and enable multi-factor authentication where applicable.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVMware · vCenter Server
WeaknessCWE-23
Added to CISA KEVJan 10, 2022
Federal patch deadlineJan 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities