Vulnerability Intelligence Report
VMware vCenter Server Remote Code Execution Vulnerability
CVE-2021-21972
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:99.52%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| n/a | VMware vCenter Server | 7.x before 7.0 U1c (affected), 6.7 before 6.7 U3l (affected), 6.5 before 6.5 U3n (affected) |
| n/a | VMware Cloud Foundation | 4.x before 4.2 (affected), 3.x before 3.10.1.2 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.518%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VMware by Broadcom · Vendor · USA |
| Reserved | 2021-01-04T00:00:00 |
| Published | 2021-02-24T16:42:05 |
| Last Updated | 2026-08-12T03:55:37 |
Community Chatter & Buzz