Critical Vulnerability in VMware vCenter Server – CVE-2021-21985
ID: 15ab1ca1-1a44-5d23-8af0-80bddfb7ad9c
STIX ID: report--15ab1ca1-1a44-5d23-8af0-80bddfb7ad9c
Feed Name: Arctic Wolf Blog
Threat Score
VMware published an advisory for CVE-2021-21985, a critical (CVSS 9.8) remote code execution vulnerability in the vSphere Client (HTML5) stemming from a lack of input validation in the Virtual SAN Health Check plug-in; an attacker with network access to port 443 could execute commands with unrestricted privileges on the vCenter host, and VMware has released patches and mitigation guidance for affected versions 6.5, 6.7, and 7.0.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
