Vulnerability record · CVE-2021-21972 · published 24 February 2021
CVE-2021-21972: VMware vCenter Server plugin path traversal leads to remote code execution
Vmware · Cloud Foundation
The vSphere Client (HTML5) in vCenter Server contains a path traversal flaw (CWE-22) in a plugin that allows an unauthenticated network attacker to upload files and execute commands with unrestricted privileges on the vCenter host OS. Because vCenter manages the virtual infrastructure, compromise of this host can expose every managed ESXi host and VM. Affected versions are vCenter Server 7.x before 7.0 U1c, 6.7 before 6.7 U3l, 6.5 before 6.5 U3n, and Cloud Foundation 4.x before 4.2 and 3.x before 3.10.1.2.
Description
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution on a high-value management host, with CVSS 9.8, KEV listing, ransomware use and near-certain EPSS score.
What it is
The vSphere Client (HTML5) in vCenter Server contains a path traversal flaw (CWE-22) in a plugin that allows an unauthenticated network attacker to upload files and execute commands with unrestricted privileges on the vCenter host OS. Because vCenter manages the virtual infrastructure, compromise of this host can expose every managed ESXi host and VM. Affected versions are vCenter Server 7.x before 7.0 U1c, 6.7 before 6.7 U3l, 6.5 before 6.5 U3n, and Cloud Foundation 4.x before 4.2 and 3.x before 3.10.1.2.
Impact
An attacker gains remote code execution as the vCenter service account, effectively full control of the vCenter Server operating system. From there they can reach managed hosts, virtual machines and stored credentials, enabling broad lateral movement and data or workload destruction.
Attack surface
Reachable over the network on port 443 of the vCenter Server; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required. Any internet- or network-exposed vCenter Server is directly at risk.
Exploitation
Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS 30-day probability is 0.99865 (99.9th percentile). Multiple public exploit references exist, so exploitation is widespread and ongoing.
What to do
- Apply the vendor updates in VMSA-2021-0002: vCenter Server 7.0 U1c, 6.7 U3l, 6.5 U3n, and Cloud Foundation 4.2 / 3.10.1.2 or later.
- If patching cannot be done immediately, remove or disable the vulnerable vRealize Operations plugin from the vSphere Client as a temporary workaround.
- Restrict network access to vCenter port 443 to trusted management networks; do not expose vCenter to the internet.
- Rotate credentials and secrets stored on or managed by any vCenter instance that may have been exposed.
- Monitor vendor and CISA guidance for the KEV due date and confirm remediation of all affected instances.
Detection
- Review vCenter and plugin logs for unexpected file uploads or writes outside expected directories, especially to web-accessible paths.
- Alert on POST requests to vSphere Client plugin endpoints from untrusted or unexpected source IPs.
- Hunt for new or modified files in vCenter web directories and for suspicious child processes spawned by the vCenter service.
- Correlate network connections to port 443 on vCenter hosts with known exploit tooling or scanning activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-21972 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "VMware vCenter Server Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-21972 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21972), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.