← العودة للجدول
CVE-2021-21972
CVE-2021-21972 — The vSphere Client (HTML5) contains a remote code execution vulnerability in a v
📅 2021-02-24
🔴 Critical 🔥 Yes NVD Exploit VMware CVSS 9.8 🎯 EPSS 93.82%

📋 الوصف الكامل

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Clou

💻 الأنظمة المتأثرة

VMware vSphere | VMware vCenter | VMware

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2021-21972

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2021-21972 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←