Thousands of VMware Center servers exposed online and potentially vulnerable to CVE-2021
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-21972 | Unauthenticated RCE in VMware vCenter Server vSphere Client Plugin CVE-2021-21972 is a remote code execution vulnerability in a plugin of the vSphere Client in VMware vCenter Server, underpinned by a path traversal flaw (CWE-23) in the plugin's file-upload functionality. It is triggered over the network through port 443: an attacker who can reach the vCenter web interface can submit crafted file-upload requests, traverse to arbitrary filesystem paths, and plant executable files on the underlying operating system. Successful exploitation yields unrestricted privileges on the vCenter host OS, giving attackers control of the central management platform for an organization's entire VMware vSphere virtualized estate. Any organization running an affected vCenter Server release whose port 443 is reachable from untrusted networks is exposed. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use and a 99.9% EPSS score (100th percentile), indicating active, widespread exploitation in the wild, though no public PoC is recorded in this data. Do: Apply the vCenter Server updates published in VMware's advisory for CVE-2021-21972 as soon as possible, prioritizing internet-facing or partner-reachable vCenter instances. Until patched, restrict access to vCenter on port 443 to trusted management networks and review access logs for unauthenticated file-upload activity against the vSphere Client upload endpoint. Because ransomware operators have actively exploited this bug, hunt for signs of compromise such as webshells or unexpected new local accounts on vCenter appliances. | 9.8 | 100% | KEV ransomware PoC ×3 |
| largetens of thousands of internet-exposed vCenter servers, with hundreds of thousands of deployments overall |
Full article457 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
February 25, 2021
![]()
A Chinese security researcher published a PoC code for the CVE-2021-21972 vulnerability in VMware Center, thousands of vulnerable servers are exposed online.
A Chinese security researcher published the Proof-of-concept exploit code for the CVE-2021-21972 RCE vulnerability affecting VMware vCenter servers.
vCenter Server is the centralized management utility for VMware, and is used to manage virtual machines, multiple ESXi hosts, and all dependent components from a single centralized location.
The flaw could be exploited by remote, unauthenticated attackers without user interaction.
“The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.” reads the advisory published. “A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. “
The issue affects vCenter Server plugin for vROPs which is available in all default installations. vROPs does not need be present to have this endpoint available. The virtualization giant has provided workarounds to disable it.
Shortly after the publication of the flaw, experts from security firm Bad Packets started observing online scanning for vulnerable servers.
https://twitter.com/bad_packets/status/1364661586070102016
At the time of this writing, querying the Shodan search engine it is possible to find more than 6,700 potentially vulnerable VMware vCenter servers that are exposed online.
The CVE-2021-21972 flaw was reported by Mikhail Klyuchnikov from Positive Technologies, it has received a CVSSv3 base score of 9.8/ 10 according to VMware’s security advisory.
Positive Technologies published a detailed analysis for this vulnerability to share knowledge about potential compromises resulting from the exploitation of this issue.
Experts from Positive Technologies decided to avoid publishing the PoC code for this issue because of the large number of installs exposed online that have yet to be patched.
Due to the amount of unpatched boxes, we've decided to hold back on publishing the PoC until somebody else releases one first. Once the exploit is public knowledge we'll also drop an article covering all of the technical details. Stay tuned!
— PT SWARM (@ptswarm) February 23, 2021
Unfortunately, ZDNet reported the availability of other easy-to-use proof-of-concept codes, exposing the organization to the risk of hack.
Experts warn of the risks that cybercrime organizations could hit vulnerable installs to compromise their networks and conduct several malicious activities, including the deployment of ransomware.
Darkside and RansomExx ransomware operators were observed targeting VMware infrastructure in the last months.
If you want to receive the weekly Security Affairs Newsletter for free subscribe here.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Avaddon ransomware)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/115001/hacking/cve-2021-21972-vmware-center-scans.html