← Vulnerability feed

Vulnerability record · CVE-2021-21972 · published 24 February 2021

CVE-2021-21972: VMware vCenter Server plugin path traversal leads to remote code execution

Vmware · Cloud Foundation

The vSphere Client (HTML5) in vCenter Server contains a path traversal flaw (CWE-22) in a plugin that allows an unauthenticated network attacker to upload files and execute commands with unrestricted privileges on the vCenter host OS. Because vCenter manages the virtual infrastructure, compromise of this host can expose every managed ESXi host and VM. Affected versions are vCenter Server 7.x before 7.0 U1c, 6.7 before 6.7 U3l, 6.5 before 6.5 U3n, and Cloud Foundation 4.x before 4.2 and 3.x before 3.10.1.2.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1% CWE-22 · Path traversal
9.8CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
9References, 6 tagged exploit
12 Aug 2026Last modified by NVD

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution on a high-value management host, with CVSS 9.8, KEV listing, ransomware use and near-certain EPSS score.

What it is

The vSphere Client (HTML5) in vCenter Server contains a path traversal flaw (CWE-22) in a plugin that allows an unauthenticated network attacker to upload files and execute commands with unrestricted privileges on the vCenter host OS. Because vCenter manages the virtual infrastructure, compromise of this host can expose every managed ESXi host and VM. Affected versions are vCenter Server 7.x before 7.0 U1c, 6.7 before 6.7 U3l, 6.5 before 6.5 U3n, and Cloud Foundation 4.x before 4.2 and 3.x before 3.10.1.2.

Impact

An attacker gains remote code execution as the vCenter service account, effectively full control of the vCenter Server operating system. From there they can reach managed hosts, virtual machines and stored credentials, enabling broad lateral movement and data or workload destruction.

Attack surface

Reachable over the network on port 443 of the vCenter Server; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required. Any internet- or network-exposed vCenter Server is directly at risk.

Exploitation

Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS 30-day probability is 0.99865 (99.9th percentile). Multiple public exploit references exist, so exploitation is widespread and ongoing.

What to do

  • Apply the vendor updates in VMSA-2021-0002: vCenter Server 7.0 U1c, 6.7 U3l, 6.5 U3n, and Cloud Foundation 4.2 / 3.10.1.2 or later.
  • If patching cannot be done immediately, remove or disable the vulnerable vRealize Operations plugin from the vSphere Client as a temporary workaround.
  • Restrict network access to vCenter port 443 to trusted management networks; do not expose vCenter to the internet.
  • Rotate credentials and secrets stored on or managed by any vCenter instance that may have been exposed.
  • Monitor vendor and CISA guidance for the KEV due date and confirm remediation of all affected instances.

Detection

  • Review vCenter and plugin logs for unexpected file uploads or writes outside expected directories, especially to web-accessible paths.
  • Alert on POST requests to vSphere Client plugin endpoints from untrusted or unexpected source IPs.
  • Hunt for new or modified files in vCenter web directories and for suspicious child processes spawned by the vCenter service.
  • Correlate network connections to port 443 on vCenter hosts with known exploit tooling or scanning activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-21972 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "VMware vCenter Server Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21972 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed9.8CVE-2024-38813VMware vCenter Server privilege escalation to root via crafted packetvCenter Server contains a privilege escalation flaw where a malicious actor with network access can send a specially crafted network packet to escala…KEVEPSS 17%analysed9.8CVE-2024-38812VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-based buffer overflow (CWE-122/CWE-787) in its DCERPC protocol implementation. A remote, unauthenticated attacker can …KEVEPSS 55%analysed9.8CVE-2024-37079VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-overflow (out-of-bounds write) in its DCERPC protocol implementation. A remote, unauthenticated attacker can send a cr…KEVEPSS 22%analysed9.8CVE-2023-34048VMware vCenter Server DCERPC out-of-bounds writevCenter Server contains an out-of-bounds write in its DCERPC protocol implementation. A remote, unauthenticated attacker with network access can trig…KEVEPSS 99%analysed9.8CVE-2022-22954VMware Workspace ONE Access and Identity Manager server-side template injection RCEVMware Workspace ONE Access and Identity Manager are affected by a server-side template injection flaw that allows remote code execution. A network-r…KEVEPSS 100%analysed9.8CVE-2021-22005VMware vCenter Server Analytics arbitrary file upload to RCEThe Analytics service in VMware vCenter Server accepts a specially crafted file upload, which the product mishandles as a path traversal issue (CWE-2…KEVEPSS 100%analysed9.8CVE-2021-21985VMware vCenter Server Virtual SAN Health Check plug-in RCEThe vSphere Client (HTML5) in vCenter Server fails to validate input in the Virtual SAN Health Check plug-in, which is enabled by default. This allow…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2021-21972), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.