ZeroHour

CVE-2021-22005

KEV ransomware PoC large

Path Traversal File Upload RCE in VMware vCenter Server (Analytics Service)

CISA: VMware vCenter Server File Upload Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2021-22005 is a path-traversal (CWE-23) file upload flaw in the Analytics service of VMware vCenter Server, the central management platform for VMware vSphere environments. An attacker with network access to the server's HTTPS port (443) can send crafted upload requests that traverse directories and write arbitrary files, achieving critical remote code execution on the vCenter host (VMware rated the flaw critical; this dataset's CVSS field was still pending). Successful exploitation gives attackers control of the vSphere management plane and, in practice, the ESXi hosts and virtual machines it manages, making it a high-value target for ransomware operators. All on-premises vCenter Server deployments of the affected versions are exposed, with internet-reachable instances at greatest risk since network access to port 443 is the only prerequisite. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS assigns a ~100% (100th percentile) probability of exploitation within 30 days, and no public proof-of-concept was known at the time of this dataset.

What to do: Upgrade to the fixed releases in VMware advisory VMSA-2021-0020 (vCenter Server 7.0 U2c, 6.7 U3o, or 6.5 U3q), or apply the vendor workaround of disabling the Analytics service if patching must be delayed. Restrict exposure of port 443 to untrusted networks, and hunt exposed vCenter servers for compromise indicators (webshells, unexpected accounts or processes) since exploitation is confirmed and ransomware campaigns are known to use this flaw.

Affected
VMware vCenter ServerVersion ranges not enumerated in the source data; per VMware advisory VMSA-2021-0020 (September 2021) the flaw affects vCenter Server 6.5, 6.7 and 7.0 prior to
Estimated exposure
largetens of thousands of internet-exposed vCenter servers (hundreds of thousands of deployments overall) — Order-of-magnitude estimate from public internet scans that indexed tens of thousands of vCenter HTTPS (443) endpoints, combined with vCenter's role as the management plane shipped with most enterprise vSphere installations.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.

CISA Known Exploited Vulnerability
Affected
VMware vCenter Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
vmware
Products
cloud foundation, vcenter server
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news