Vulnerability record · CVE-2021-21985 · published 26 May 2021
CVE-2021-21985: VMware vCenter Server Virtual SAN Health Check plug-in RCE
Vmware · Vcenter Server
The vSphere Client (HTML5) in vCenter Server fails to validate input in the Virtual SAN Health Check plug-in, which is enabled by default. This allows an unauthenticated network attacker to execute commands with unrestricted privileges on the vCenter host operating system. Because vCenter is a high-value management plane, compromise can cascade to the whole virtual estate.
Description
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network RCE in a default-enabled vCenter component, listed in KEV with known ransomware use and near-maximum EPSS.
What it is
The vSphere Client (HTML5) in vCenter Server fails to validate input in the Virtual SAN Health Check plug-in, which is enabled by default. This allows an unauthenticated network attacker to execute commands with unrestricted privileges on the vCenter host operating system. Because vCenter is a high-value management plane, compromise can cascade to the whole virtual estate.
Impact
An attacker gains remote code execution as the vCenter Server process, effectively full control of the underlying host OS. From there they can reach managed ESXi hosts, virtual machines and stored credentials.
Attack surface
Reachable over the network on port 443 of the vCenter Server; the CVSS vector shows no privileges required and no user interaction. The vulnerable plug-in is enabled by default, so no special configuration is needed to expose it.
Exploitation
Listed in CISA KEV with a 2021-11-03 addition and flagged for known ransomware campaign use, and EPSS 30-day probability is 0.99999. Public exploit code is referenced (Packet Storm exploit entry), so exploitation is active and widespread.
What to do
- Apply the VMware updates in VMSA-2021-0010 to vCenter Server and Cloud Foundation immediately.
- If patching cannot be done at once, disable the Virtual SAN Health Check plug-in per VMware guidance.
- Restrict network access to vCenter port 443 to trusted management networks only.
- Rotate credentials and secrets stored on or reachable from vCenter after any suspected exposure.
- Monitor KEV due date (2021-11-17) compliance and confirm remediation in asset inventory.
Detection
- Hunt vCenter and vpxd logs for requests to the Virtual SAN Health Check plug-in endpoints, especially unusual or malformed parameters.
- Alert on unexpected child processes spawned by the vCenter/vpxd service, such as shells or scripting interpreters.
- Monitor outbound connections from vCenter hosts to unfamiliar external addresses for post-exploitation activity.
- Review authentication and access logs for anomalous access to port 443 from non-management networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-21985 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "VMware vCenter Server Improper Input Validation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/162812/VMware-Security-Advisory-2021-0010.html | Third Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/163487/VMware-vCenter-Server-Virtual-SAN-Health-Check-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.vmware.com/security/advisories/VMSA-2021-0010.html | Vendor Advisory |
| http://packetstormsecurity.com/files/162812/VMware-Security-Advisory-2021-0010.html | Third Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/163487/VMware-vCenter-Server-Virtual-SAN-Health-Check-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.vmware.com/security/advisories/VMSA-2021-0010.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21985 | US Government Resource |
Track CVE-2021-21985 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21985), CISA KEV, FIRST EPSS (scores of 2026-09-17). This page is refreshed as NVD updates the record.