The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
CVE-2021-21985 viene sfruttato?
Inserito nel catalogo CISA KEV il 2021-11-03.
Scadenza di remediation federale: 2021-11-17.
Oltre quella data da 1732 giorni.
Usato in campagne ransomware.
EPSS stima la probabilità di sfruttamento nei prossimi 30 giorni al 100.0%.
Codice di exploit pubblico: integrato in uno strumento pubblico.
Esistono regole di detection pubbliche.
Quali prodotti e versioni sono interessati?
Nessun elenco di pacchetti interessati registrato qui.