ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

ALERT: Critical RCE Bug in VMware vCenter Server Under Active Attack

criticalVulnerability exploited in the wildimportance 60CVE-2021-21985CVE-2021-21972

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-21972
Unauthenticated RCE in VMware vCenter Server vSphere Client Plugin

CVE-2021-21972 is a remote code execution vulnerability in a plugin of the vSphere Client in VMware vCenter Server, underpinned by a path traversal flaw (CWE-23) in the plugin's file-upload functionality. It is triggered over the network through port 443: an attacker who can reach the vCenter web interface can submit crafted file-upload requests, traverse to arbitrary filesystem paths, and plant executable files on the underlying operating system. Successful exploitation yields unrestricted privileges on the vCenter host OS, giving attackers control of the central management platform for an organization's entire VMware vSphere virtualized estate. Any organization running an affected vCenter Server release whose port 443 is reachable from untrusted networks is exposed. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use and a 99.9% EPSS score (100th percentile), indicating active, widespread exploitation in the wild, though no public PoC is recorded in this data.

Do: Apply the vCenter Server updates published in VMware's advisory for CVE-2021-21972 as soon as possible, prioritizing internet-facing or partner-reachable vCenter instances. Until patched, restrict access to vCenter on port 443 to trusted management networks and review access logs for unauthenticated file-upload activity against the vSphere Client upload endpoint. Because ransomware operators have actively exploited this bug, hunt for signs of compromise such as webshells or unexpected new local accounts on vCenter appliances.

9.8100% KEV ransomware PoC ×3
  • VMware vCenter Server
largetens of thousands of internet-exposed vCenter servers, with hundreds of thousands of deployments overall
CVE-2021-21985
Remote Code Execution in VMware vCenter Server vSAN Health Check plug-in

CVE-2021-21985 is an improper input validation flaw (CWE-20, with related unsafe reflection CWE-470 and SSRF CWE-918 classifications) in the Virtual SAN Health Check plug-in of the VMware vSphere Client, which is enabled by default in vCenter Server. It is triggered by crafted requests sent to the plug-in over the network; VMware indicated that network access to vCenter's HTTPS port (443) is sufficient to reach the vulnerable component. A successful attacker gains remote code execution with unrestricted privileges on the underlying operating system hosting vCenter Server, a highly privileged position in the virtualization stack. Any organization running an affected VMware vCenter Server is affected; because vCenter is the default management plane for vSphere, this spans a very large share of enterprise virtualization estates, with tens of thousands of instances directly exposed to the internet. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use and requires applying vendor updates, and EPSS puts the 30-day exploitation probability at essentially 100%, though the source data lists no public PoC.

Do: Update vCenter Server per VMware's instructions; fixes shipped in May 2021 for the 6.5, 6.7, and 7.0 branches (e.g., 6.5 U3n, 6.7 U3o, and 7.0 U2c — verify your current build against the vendor advisory). Until patched, restrict access to vCenter's HTTPS (443) interface to trusted management networks rather than the open internet, and review appliance logs and running processes for indicators of exploitation, since ransomware operators are known to use this flaw after gaining network access.

9.8100% KEV ransomware PoC
  • VMware vCenter Server
largetens of thousands of internet-exposed vCenter servers (public scan data), with a total installed base likely in the hundreds of thousands

Indicators of compromiseAll →

TypeIndicatorContext
ipv4104.40.252.159rcher Kevin Beaumont. "Mass scanning activity detected from 104.40.252.159 checking for VMware vSphere hosts vulnerable to remote code
Full article350 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJun 05, 2021

Malicious actors are actively mass scanning the internet for vulnerable VMware vCenter servers that are unpatched against a critical remote code execution flaw, which the company addressed late last month.

The ongoing activity was detected by Bad Packets on June 3 and corroborated yesterday by security researcher Kevin Beaumont. "Mass scanning activity detected from 104.40.252.159 checking for VMware vSphere hosts vulnerable to remote code execution," tweeted Troy Mursch, chief research officer at Bad Packets.

The development follows the publication of a proof-of-concept (PoC) RCE exploit code targeting the VMware vCenter bug.

Tracked as CVE-2021-21985 (CVSS score 9.8), the issue is a consequence of a lack of input validation in the Virtual SAN (vSAN) Health Check plug-in, which could be abused by an attacker to execute commands with unrestricted privileges on the underlying operating system that hosts the vCenter Server.

Although the flaw was rectified by VMware on May 25, the company strongly urged its customers to apply the emergency change immediately. "In this era of ransomware it is safest to assume that an attacker is already inside the network somewhere, on a desktop and perhaps even in control of a user account, which is why we strongly recommend declaring an emergency change and patching as soon as possible," VMware said.

This is not the first time adversaries have opportunistically mass scanned the internet for vulnerable VMware vCenter servers. A similar remote code execution vulnerability (CVE-2021-21972) that was patched by VMware in February became the target of cyber threat actors attempting to exploit and take control of unpatched systems.

At least 14,858 vCenter servers were found reachable over the internet at the time, according to Bad Packets and Binary Edge.

What's more, a new research from Cisco Talos earlier this week found that the threat actor behind the Python-based Necro bot wormed its way into exposed VMware vCenter servers by abusing the same security weakness to boost the malware's infection propagation capabilities.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/06/alert-critical-rce-bug-in-vmware.html