CVE-2021-22005
ID: a775a07f-38d1-5c03-96f1-650982ae010c
STIX ID: report--a775a07f-38d1-5c03-96f1-650982ae010c
Feed Name: Arctic Wolf Blog
Threat Score
VMware released a patch advisory for CVE-2021-22005, a critical (CVSS 9.8) arbitrary-file-upload vulnerability in vCenter Server and VMware Cloud Foundation that can yield unauthenticated remote code execution via port 443. Partial PoC code has been published and threat actors are scanning for exposed vCenter instances; Arctic Wolf recommends immediate patching or applying VMware’s temporary workaround to mitigate likely ransomware-targeting exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
