VMware Warns of Critical File Upload Vulnerability Affecting vCenter Server
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-21991 +1 in the same advisory: …21992 | The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administrative user access on vCenter Server host may exploit this issue to escalate privileges to Administrator on the vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash). NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2021-22015 | The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their privileges to root on vCenter Server Appliance. NVD description · AI analysis pending | 7.8 group max | 2% | PoC |
| — | |
| CVE-2021-22005 +1 in the same advisory: …22017 | Path Traversal File Upload RCE in VMware vCenter Server (Analytics Service) CVE-2021-22005 is a path-traversal (CWE-23) file upload flaw in the Analytics service of VMware vCenter Server, the central management platform for VMware vSphere environments. An attacker with network access to the server's HTTPS port (443) can send crafted upload requests that traverse directories and write arbitrary files, achieving critical remote code execution on the vCenter host (VMware rated the flaw critical; this dataset's CVSS field was still pending). Successful exploitation gives attackers control of the vSphere management plane and, in practice, the ESXi hosts and virtual machines it manages, making it a high-value target for ransomware operators. All on-premises vCenter Server deployments of the affected versions are exposed, with internet-reachable instances at greatest risk since network access to port 443 is the only prerequisite. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS assigns a ~100% (100th percentile) probability of exploitation within 30 days, and no public proof-of-concept was known at the time of this dataset. Do: Upgrade to the fixed releases in VMware advisory VMSA-2021-0020 (vCenter Server 7.0 U2c, 6.7 U3o, or 6.5 U3q), or apply the vendor workaround of disabling the Analytics service if patching must be delayed. Restrict exposure of port 443 to untrusted networks, and hunt exposed vCenter servers for compromise indicators (webshells, unexpected accounts or processes) since exploitation is confirmed and ransomware campaigns are known to use this flaw. | 9.8 group max | 100% | KEV ransomware PoC |
| largetens of thousands of internet-exposed vCenter servers (hundreds of thousands of deployments overall) |
Full article528 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 22, 2021
VMware on Tuesday published a new bulletin warning of as many as 19 vulnerabilities in vCenter Server and Cloud Foundation appliances that a remote attacker could exploit to take control of an affected system.
The most urgent among them is an arbitrary file upload vulnerability in the Analytics service (CVE-2021-22005) that impacts vCenter Server 6.7 and 7.0 deployments. "A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file," the company noted, adding "this vulnerability can be used by anyone who can reach vCenter Server over the network to gain access, regardless of the configuration settings of vCenter Server."
Although VMware has published workarounds for the flaw, the company cautioned that they are "meant to be a temporary solution until updates […] can be deployed."
The complete list of flaws patched by the virtualization services provider is as follows —
- CVE-2021-22005 (CVSS score: 9.8) - vCenter Server file upload vulnerability
- CVE-2021-21991 (CVSS score: 8.8) - vCenter Server local privilege escalation vulnerability
- CVE-2021-22006 (CVSS score: 8.3) - vCenter Server reverse proxy bypass vulnerability
- CVE-2021-22011 (CVSS score: 8.1) - vCenter server unauthenticated API endpoint vulnerability
- CVE-2021-22015 (CVSS score: 7.8) - vCenter Server improper permission local privilege escalation vulnerabilities
- CVE-2021-22012 (CVSS score: 7.5) - vCenter Server unauthenticated API information disclosure vulnerability
- CVE-2021-22013 (CVSS score: 7.5) - vCenter Server file path traversal vulnerability
- CVE-2021-22016 (CVSS score: 7.5) - vCenter Server reflected XSS vulnerability
- CVE-2021-22017 (CVSS score: 7.3) - vCenter Server rhttpproxy bypass vulnerability
- CVE-2021-22014 (CVSS score: 7.2) - vCenter Server authenticated code execution vulnerability
- CVE-2021-22018 (CVSS score: 6.5) - vCenter Server file deletion vulnerability
- CVE-2021-21992 (CVSS score: 6.5) - vCenter Server XML parsing denial-of-service vulnerability
- CVE-2021-22007 (CVSS score: 5.5) - vCenter Server local information disclosure vulnerability
- CVE-2021-22019 (CVSS score: 5.3) - vCenter Server denial of service vulnerability
- CVE-2021-22009 (CVSS score: 5.3) - vCenter Server VAPI multiple denial of service vulnerabilities
- CVE-2021-22010 (CVSS score: 5.3) - vCenter Server VPXD denial of service vulnerability
- CVE-2021-22008 (CVSS score: 5.3) - vCenter Server information disclosure vulnerability
- CVE-2021-22020 (CVSS score: 5.0) - vCenter Server Analytics service denial-of-service vulnerability
- CVE-2021-21993 (CVSS score: 4.3) - vCenter Server SSRF vulnerability
Credited with reporting most of the flaws are George Noseevich and Sergey Gerasimov of SolidLab LLC, alongside Hynek Petrak of Schneider Electric, Yuval Lazar of Pentera, and Osama Alaa of Malcrove.
"The ramifications of [CVE-2021-22005] are serious and it is a matter of time – likely minutes after the disclosure – before working exploits are publicly available," VMware said in an FAQ urging customers to immediately update their vCenter installations.
"With the threat of ransomware looming nowadays the safest stance is to assume that an attacker may already have control of a desktop and a user account through the use of techniques like phishing or spear-phishing, and act accordingly. This means the attacker may already be able to reach vCenter Server from inside a corporate firewall, and time is of the essence," the company added.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/09/vmware-warns-of-critical-file-upload.html