[ SB 21.19 ] VMWare vCenter RCE (CVE-2021-22005)

VMWare vCenter Server contains an RCE-vulnerability in the Analytics service. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

Patches and Workarounds are available.

A public POC was available within 12hrs, and mass-scanning and exploitation already happened within 24hrs after publication.

scanning

scanning

References

more on POCs





Fragen? Kontakt: info@zero.bs