← Vulnerability feed

Vulnerability record · CVE-2021-21999 · published 23 June 2021

CVE-2021-21999: Vmware app volumes uncontrolled search path element vulnerability

Vmware · App Volumes

VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerability. An attacker with normal access to a virtual machine may exploit this issue by placing a malicious file renamed as `openssl.cnf' in an unrestricted directory which would allow code to be executed with elevated privileges.

7.8 CVSS 3.1 High EPSS 1.5% · top 27.2% CWE-427 · Uncontrolled search path element
7.8CVSS 3.1 base score, v2 7.2
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerability. An attacker with normal access to a virtual machine may exploit this issue by placing a malicious file renamed as `openssl.cnf' in an unrestricted directory which would allow code to be executed with elevated privileges.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21999 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2025-41244VMware Aria Operations and Tools local privilege escalation to rootVMware Aria Operations and VMware Tools contain a local privilege escalation flaw where a non-administrative local actor on a VM with VMware Tools in…KEVEPSS 8.4%analysed7.8CVE-2020-3950VMware Fusion, VMRC and Horizon Client setuid privilege escalationVMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac mishandle setuid binaries, allowing a local user to gain root. The flaw affec…KEVEPSS 7.3%analysed3.9CVE-2023-20867VMware Tools authentication bypass from compromised ESXi hostVMware Tools can be forced by a fully compromised ESXi host to fail authentication of host-to-guest operations. This lets a host-level attacker tampe…KEVEPSS 14%analysed8.8CVE-2019-5527Vmware horizon use after free vulnerabilityESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the sever…EPSS 0.30%7.8CVE-2023-34057Vmware tools improper privilege management vulnerabilityVMware Tools contains a local privilege escalation vulnerability. A malicious actor with local user access to a guest virtual machine may elevate pri…EPSS 0.19%7.8CVE-2022-31676Vmware tools improper privilege management vulnerabilityVMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access …EPSS 0.54%7.8CVE-2020-3974Vmware fusion vulnerabilityVMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.…EPSS 0.36%7.8CVE-2019-5543Vmware horizon client incorrect permission assignment vulnerabilityFor VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware Workstation for Wi…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2021-21999), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.