← Vulnerability feed

Vulnerability record · CVE-2021-21974 · published 24 February 2021

CVE-2021-21974: VMware ESXi OpenSLP heap overflow allows remote code execution

Vmware · Cloud Foundation

OpenSLP as shipped in VMware ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) contains a heap-overflow (out-of-bounds write, CWE-787). An attacker on the same network segment who can reach port 427 can trigger the overflow in the OpenSLP service and achieve remote code execution. Because ESXi is a hypervisor, compromise of the host puts every guest and its data at risk.

8.8 CVSS 3.1 High EPSS 45% · top 1.3% CWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score, v2 5.8
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityRemote code execution on a hypervisor with a public exploit and documented ransomware use, though exploitation requires same-segment network access rather than internet exposure.

What it is

OpenSLP as shipped in VMware ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) contains a heap-overflow (out-of-bounds write, CWE-787). An attacker on the same network segment who can reach port 427 can trigger the overflow in the OpenSLP service and achieve remote code execution. Because ESXi is a hypervisor, compromise of the host puts every guest and its data at risk.

Impact

Successful exploitation gives the attacker remote code execution on the ESXi host, enabling full control of the hypervisor and the virtual machines it runs. The ESXiArgs ransomware campaign is documented as using this flaw, so data destruction and encryption are realistic outcomes.

Attack surface

Reachable over the network from the same segment via the OpenSLP service on port 427; the CVSS vector is AV:A/PR:N/UI:N, so no authentication and no user interaction are required. The attacker only needs adjacency to the ESXi management network, not internet exposure.

Exploitation

An exploit is publicly referenced (Packet Storm, tagged Exploit), and ESXiArgs is documented as using this vulnerability. It is not listed in CISA KEV, but EPSS is high at 0.45063 (98.7th percentile), indicating elevated real-world exploitation likelihood.

What to do

  • Patch ESXi to the fixed builds named in the advisory: 7.0 ESXi70U1c-17325551, 6.7 ESXi670-202102401-SG, 6.5 ESXi650-202102101-SG.
  • If patching cannot be done immediately, disable the OpenSLP service (slpd) on ESXi hosts.
  • Restrict access to port 427 so only trusted management hosts on the same segment can reach it; do not expose ESXi management interfaces broadly.
  • Segment and firewall ESXi management networks away from general user and workload networks.
  • Verify no unauthorized changes or new accounts on hosts, given documented ransomware use.

Detection

  • Monitor network traffic to TCP/UDP port 427 on ESXi hosts for unexpected or anomalous connections.
  • Alert on slpd process crashes or restarts on ESXi hosts, which can indicate heap-overflow attempts.
  • Hunt for ESXiArgs-related artifacts such as ransom notes and encrypted VM files on datastores.
  • Audit ESXi host logs and configuration for unexpected changes following suspected exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

Ransomware crews whose documented playbooks reference this CVE: