CVE-2021-21985
KEV RANSOMWAREHIGH 10.0EPSS 100.0%
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03, used in ransomware campaigns
- Nuclei
- critical · CWE-20
- Published
- 2021-05-26
- Updated
- 2026-08-12
Proof-of-concept exploits (12)
- http://packetstormsecurity.com/files/163487/VMware-vCenter-Server-Virtual-SAN-Health-Chec…
- aristosMiliaressis/CVE-2021-219850★ · 2021-07-11
- bigbroke/CVE-2021-219851★ · 2021-05-27
- daedalus/CVE-2021-219852★ · 2023-11-27
- haiclover/CVE-2021-219851★ · 2021-07-12
- haidv35/CVE-2021-219851★ · 2021-07-12
- mauricelambert/CVE-2021-219850★ · 2021-06-01
- sknux/CVE-2021-21985_PoC3★ · 2021-11-09
- testanull/Project_CVE-2021-21985_PoC29★ · 2021-06-07
- xnianq/cve-2021-21985_exp115★ · 2022-01-10
- zidanfanshao/vcenter_tools70★ · 2024-11-17
- alt3kx/CVE-2021-21985_PoC
Nuclei templates (1)
Metasploit modules (1)
Exploit collections (3)
- chaitin/xray/blob/master/pocs/vmware-vcenter-cve-2021-21985-rce.yml
- helloexp/0day/tree/master/94-%E5%B8%B8%E7%94%A8%E8%BD%AF%E4%BB%B6%E4%B8%93%E5%8C%BA/14-VM…
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2021/CVE-2021-21985.yaml