CVE-2021-21972

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
93.821

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in VMware vCenter 6.5Windows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-aWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-bWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-cWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-dWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-eWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-fWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-u1dWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-u1eWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-u1gWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-u2Windows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-u2bWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-u2cWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-u2dWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-u2gWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-u3Windows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-u3dWindows
Vulnerabilities CVE-2021-21972,CVE-2021-21973,CVE-2021-21985,CVE-2021-21986 are affected in VMware vCenter 6.5-u3fWindows
Vulnerabilities CVE-2021-21972,CVE-2021-21973,CVE-2021-21985,CVE-2021-21986 are affected in VMware vCenter 6.5-u3kWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-update1dWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-update1eWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-update1gWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-update2Windows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-update2bWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-update2cWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-update2dWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-update2gWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-update3Windows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-update3dWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-update3fWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.5-update3kWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.7Windows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-aWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-bWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-dWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-u1Windows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-u1bWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-u2Windows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-u2aWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-u2cWindows
Vulnerabilities CVE-2021-21972,CVE-2021-21973,CVE-2021-21985 are affected in VMware vCenter 6.7-u3Windows
Vulnerabilities CVE-2021-21972,CVE-2021-21973,CVE-2021-21985 are affected in VMware vCenter 6.7-u3aWindows
Vulnerabilities CVE-2021-21972,CVE-2021-21973,CVE-2021-21985 are affected in VMware vCenter 6.7-u3bWindows
Vulnerabilities CVE-2021-21972,CVE-2021-21973,CVE-2021-21985 are affected in VMware vCenter 6.7-u3fWindows
Vulnerabilities CVE-2021-21972,CVE-2021-21973,CVE-2021-21985 are affected in VMware vCenter 6.7-u3gWindows
Vulnerabilities CVE-2021-21972,CVE-2021-21973,CVE-2021-21985 are affected in VMware vCenter 6.7-u3jWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-update1Windows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-update1bWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-update2Windows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-update2aWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-update2cWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-update3Windows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-update3aWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-update3bWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-update3fWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-update3gWindows
Multiple Vulnerabilities are affected in VMware vCenter 6.7-update3jWindows
Multiple Vulnerabilities are affected in VMware vCenter 7.0Windows
Multiple Vulnerabilities are affected in VMware vCenter 7.0-aWindows
Multiple Vulnerabilities are affected in VMware vCenter 7.0-bWindows
Multiple Vulnerabilities are affected in VMware vCenter 7.0-cWindows
Multiple Vulnerabilities are affected in VMware vCenter 7.0-dWindows
Vulnerabilities CVE-2021-21972,CVE-2021-21973 are affected in VMware vCenter 7.0-u1Windows
Vulnerabilities CVE-2021-21972,CVE-2021-21973 are affected in VMware vCenter 7.0-u1aWindows
Multiple Vulnerabilities are affected in VMware vCenter 7.0-update1Windows
Multiple Vulnerabilities are affected in VMware vCenter 7.0-update1aWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5Windows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-u3dWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-aWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-bWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-cWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-dWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-u1dWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-u1eWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-u1gWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-u2Windows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-u2bWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-u2cWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-u2dWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-u2gWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-update1dWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-update1eWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-update1gWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-update2Windows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-update2bWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-update2cWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-update2dWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-update2gWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7Windows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-aWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-bWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-dWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-u1Windows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-u1bWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-u2Windows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-u2aWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-u2cWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-update1Windows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-update1bWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-update2Windows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-update2aWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-update2cWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-eWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-fWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-update3Windows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-update3dWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-update3fWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-update3Windows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-update3aWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-update3bWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-update3fWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-update3gWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 7.0Windows
Multiple Vulnerabilities are affected in VMware vCenter Server 7.0-aWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-u3Windows
Vulnerabilities CVE-2021-21972,CVE-2021-21973,CVE-2021-21985,CVE-2021-21986 are affected in VMware vCenter Server 6.5-u3fWindows
Vulnerabilities CVE-2021-21972,CVE-2021-21973,CVE-2021-21985,CVE-2021-21986 are affected in VMware vCenter Server 6.5-u3kWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.5-update3kWindows
Vulnerabilities CVE-2021-21972,CVE-2021-21973,CVE-2021-21985 are affected in VMware vCenter Server 6.7-u3Windows
Vulnerabilities CVE-2021-21972,CVE-2021-21973,CVE-2021-21985 are affected in VMware vCenter Server 6.7-u3aWindows
Vulnerabilities CVE-2021-21972,CVE-2021-21973,CVE-2021-21985 are affected in VMware vCenter Server 6.7-u3bWindows
Vulnerabilities CVE-2021-21972,CVE-2021-21973,CVE-2021-21985 are affected in VMware vCenter Server 6.7-u3fWindows
Vulnerabilities CVE-2021-21972,CVE-2021-21973,CVE-2021-21985 are affected in VMware vCenter Server 6.7-u3gWindows
Vulnerabilities CVE-2021-21972,CVE-2021-21973,CVE-2021-21985 are affected in VMware vCenter Server 6.7-u3jWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 6.7-update3jWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 7.0-bWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 7.0-cWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 7.0-dWindows
Vulnerabilities CVE-2021-21972,CVE-2021-21973 are affected in VMware vCenter Server 7.0-u1Windows
Vulnerabilities CVE-2021-21972,CVE-2021-21973 are affected in VMware vCenter Server 7.0-u1aWindows
Multiple Vulnerabilities are affected in VMware vCenter Server 7.0-update1Windows
Multiple Vulnerabilities are affected in VMware vCenter Server 7.0-update1aWindows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234