Description
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- VMware / Cloud Foundation3.0 – 3.10.1.2
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.5 – 6.5
- VMware / vCenter Server6.7 – 6.7
- VMware / vCenter Server6.7 – 6.7
- VMware / vCenter Server6.7 – 6.7
- VMware / vCenter Server6.7 – 6.7
- VMware / vCenter Server6.7 – 6.7
- VMware / vCenter Server6.7 – 6.7
- VMware / vCenter Server6.7 – 6.7
- VMware / vCenter Server6.7 – 6.7
- VMware / vCenter Server6.7 – 6.7
- VMware / vCenter Server6.7 – 6.7
- VMware / vCenter Server6.7 – 6.7
- VMware / vCenter Server6.7 – 6.7
- VMware / vCenter Server6.7 – 6.7
- VMware / vCenter Server6.7 – 6.7
- VMware / vCenter Server6.7 – 6.7
- VMware / vCenter Server7.0 – 7.0
- VMware / vCenter Server7.0 – 7.0
- VMware / vCenter Server7.0 – 7.0
- VMware / vCenter Server7.0 – 7.0
- VMware / vCenter Server7.0 – 7.0
- VMware / vCenter Server7.0 – 7.0
- VMware / vCenter Server7.0 – 7.0
Exploits & proofs of concept
- exploit-dbVMware vCenter Server 7.0 - Remote Code Execution (RCE) (Unauthenticated)by CHackA0101
- exploit-dbVMware vCenter Server 7.0 - Unauthenticated File Uploadby Photubias
- nucleiVMware vSphere Client (HTML5) - Remote Code Executionby dwisiswant0
References
- VENDOR_ADVISORYhttps://www.vmware.com/security/advisories/VMSA-2021-0002.html
- EXPLOIThttp://packetstormsecurity.com/files/161590/VMware-vCenter-Server-7.0-Arbitrary-File-Upload.html
- EXPLOIThttp://packetstormsecurity.com/files/161695/VMware-vCenter-Server-File-Upload-Remote-Code-Execution.html
- EXPLOIThttp://packetstormsecurity.com/files/163268/VMware-vCenter-6.5-6.7-7.0-Remote-Code-Execution.html
Updated 13m ago · 8 sources