logo

VMware CVE-2021-22005 Technical & Impact analysis

ID: b2f4c9cb-fd4f-59de-8f4f-09663a0b7e73

STIX ID: report--b2f4c9cb-fd4f-59de-8f4f-09663a0b7e73

Feed Name: Censys Blog

Threat Score
90/100

Date Published: 2021-09-24

Date Updated: 2026-04-27

...
...

This report analyzes CVE-2021-22005, a critical (CVSS 9.8) unauthenticated RCE in VMware vCenter's analytics service that allows an attacker to control log file paths via request parameters and write arbitrary files as root (including to /etc/cron.d to achieve code execution). It includes root-cause analysis, exploit PoC details, detection techniques for vulnerable hosts and signs of compromise, and remediation guidance to patch or apply the provided workaround.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.