The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
Published: 2021-05-25
VMware has issued patches for a critical remote code execution vulnerability in vCenter Server. Organizations are strongly encouraged to apply patches as soon as possible. Update June 2: The Identifying Affected Systems section has been updated to include audit checks for the workaround. Update June 4: The Proof of Concept section has been updated to reflect the publication of exploit code and active scanning for vulnerable servers.
https://www.tenable.com/cyber-exposure/a-look-inside-the-ransomware-ecosystem
https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-117a
https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-209a
https://github.com/J3ff-R3y/network-scanner-cmdb
https://github.com/b4nxzz/CVEs
https://github.com/Schira4396/VcenterKiller
https://github.com/sknux/CVE-2021-21985_PoC
https://github.com/daedalus/CVE-2021-21985
https://github.com/r0ckysec/CVE-2021-21985
https://github.com/mauricelambert/CVE-2021-21985
https://github.com/onSec-fr/CVE-2021-21985-Checker
https://www.vmware.com/security/advisories/VMSA-2021-0010.html
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21985