Drop everything and patch VMware’s vCenter Server Vulnerabilities
Drop everything and patch VMware’s vCenter Server Vulnerabilities
THREAT LEVEL: Green.
For a detailed advisory, download the pdf file here.
VMware has issued patches for 19 new vulnerabilities. CVE-2021-22005 is the worst of the lot, defined as “an arbitrary file upload vulnerability in the Analytics service” of the vCenter Server. An attacker with network access to vCenter Server’s port 443 might use this flaw to execute code on the server by uploading a specially crafted file. VMware also provides a temporary workaround for individuals who are unable to instantly patch their appliances.
Vulnerability Details



Patch Link
https://www.vmware.com/security/advisories/VMSA-2021-0020.html
References
https://blogs.vmware.com/vsphere/2021/09/vmsa-2021-0020-what-you-need-to-know.html
https://www.theregister.com/2021/09/22/vmware_emergency_vcenter_patch_recommendation/