CVE-2021-21972
criticalCVSS v3 Base Score
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
99.5%
Exploitation probability in 30 days
Top 0% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
High
Availability
High
Published: February 24, 2021 (2020 days ago)
Last Modified: August 12, 2026
Vendor: VMware
Source: NVD
⚠️ CISA Known Exploited Vulnerability
Added to KEV: 2021-11-03
Remediation Due: 2021-11-17 (⚠ 1754d overdue)
Ransomware Campaign: Known
Vulnerability Report
Generated by CyberWatcher
Description
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
CWE
CWE-22Affected Products
vmware cloud foundationvmware vcenter server