Drop everything and patch VMware’s vCenter Server Vulnerabilities

Threat Advisories

Drop everything and patch VMware’s vCenter Server Vulnerabilities

THREAT LEVEL: Green.

For a detailed advisory, download the pdf file here.

VMware has issued patches for 19 new vulnerabilities. CVE-2021-22005 is the worst of the lot, defined as “an arbitrary file upload vulnerability in the Analytics service” of the vCenter Server. An attacker with network access to vCenter Server’s port 443 might use this flaw to execute code on the server by uploading a specially crafted file. VMware also provides a temporary workaround for individuals who are unable to instantly patch their appliances.

Vulnerability Details

Patch Link

https://www.vmware.com/security/advisories/VMSA-2021-0020.html

References

https://blogs.vmware.com/vsphere/2021/09/vmsa-2021-0020-what-you-need-to-know.html

https://www.theregister.com/2021/09/22/vmware_emergency_vcenter_patch_recommendation/