CVE-2021-21972
KEV RANSOMWAREHIGH 10.0EPSS 99.9%
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 99.87% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03, used in ransomware campaigns
- Nuclei
- critical · CWE-22
- Published
- 2021-02-24
- Updated
- 2026-08-12
Proof-of-concept exploits (35)
- http://packetstormsecurity.com/files/161590/VMware-vCenter-Server-7.0-Arbitrary-File-Uplo…
- http://packetstormsecurity.com/files/161695/VMware-vCenter-Server-File-Upload-Remote-Code…
- http://packetstormsecurity.com/files/163268/VMware-vCenter-6.5-6.7-7.0-Remote-Code-Execut…
- B1anda0/CVE-2021-2197211★ · 2021-02-25
- ByZain/CVE-2021-219723★ · 2021-03-04
- DougCarroll/CVE_2021_219720★ · 2021-02-28
- GuayoyoCyber/CVE-2021-2197229★ · 2021-03-03
- L-pin/CVE-2021-219721★ · 2021-02-26
- Ma1Dong/vcenter_rce11★ · 2021-03-01
- NS-Sp4ce/CVE-2021-21972498★ · 2023-06-08
- QmF0c3UK/CVE-2021-21972-vCenter-6.5-7.0-RCE-POC136★ · 2021-03-01
- TAI-REx/CVE-2021-219720★ · 2021-02-25
- TaroballzChen/CVE-2021-2197219★ · 2021-03-07
- Vulnmachines/VmWare-vCenter-vulnerability8★ · 2022-07-26
- byteofandri/CVE-2021-2197211★ · 2022-03-07
- byteofjoshua/CVE-2021-2197211★ · 2022-03-07
- conjojo/VMware_vCenter_UNAuthorized_RCE_CVE-2021-2197227★ · 2021-02-25
- d3sh1n/cve-2021-219720★ · 2021-03-11
- haiclover/CVE-2021-219723★ · 2021-08-02
- haidv35/CVE-2021-219723★ · 2021-08-02
- horizon3ai/CVE-2021-21972269★ · 2021-02-25
- milo2012/CVE-2021-2197233★ · 2021-03-01
- murataydemir/CVE-2021-219726★ · 2021-04-06
- orangmuda/CVE-2021-2197211★ · 2022-03-07
- pettyhacks/vSphereyeeter3★ · 2022-07-21
- renini/CVE-2021-219722★ · 2021-02-25
- robwillisinfo/VMware_vCenter_CVE-2021-219721★ · 2021-02-27
- saucer-man/exploit11★ · 2021-07-09
- stevenp322/cve-2021-219720★ · 2021-08-27
- stevenp322/vSphereYeeter0★ · 2021-08-27
- vikerup/Get-vSphereVersion2★ · 2023-04-27
- viksafe/Get-vSphereVersion2★ · 2023-04-27
- yaunsky/CVE-2021-219728★ · 2021-02-24
- zidanfanshao/vcenter_tools70★ · 2024-11-17
- alt3kx/CVE-2021-21972
Nuclei templates (1)
Metasploit modules (1)
ExploitDB entries (2)
Exploit collections (4)
- chaitin/xray/blob/master/pocs/vmware-vcenter-unauthorized-rce-cve-2021-21972.yml
- helloexp/0day/tree/master/00-CVE_EXP/CVE-2021-21972
- tzwlhack/Vulnerability/blob/main/VMware%20vCenter%20Server%20%E8%BF%9C%E7%A8%8B%E6%89%A7%…
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2021/CVE-2021-21972.yaml