VMware CVE-2021-22005 Technical & Impact analysis
ID: b2f4c9cb-fd4f-59de-8f4f-09663a0b7e73
STIX ID: report--b2f4c9cb-fd4f-59de-8f4f-09663a0b7e73
Feed Name: Censys Blog
Threat Score
This report analyzes CVE-2021-22005, a critical (CVSS 9.8) unauthenticated RCE in VMware vCenter's analytics service that allows an attacker to control log file paths via request parameters and write arbitrary files as root (including to /etc/cron.d to achieve code execution). It includes root-cause analysis, exploit PoC details, detection techniques for vulnerable hosts and signs of compromise, and remediation guidance to patch or apply the provided workaround.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
