CVE-2021-22005
VMware vCenter Server File Upload Vulnerability
Description
CVE-2021-22005 is a critical arbitrary file upload vulnerability in VMware vCenter Server that allows a malicious actor with network access to port 443 to execute code on the server by uploading a specially crafted file to the Analytics service. This VMware vCenter Server vulnerability has a CVSS 3.1 score of 9.8 (CRITICAL) and has been actively exploited in the wild, as confirmed by its inclusion in the CISA Known Exploited Vulnerabilities catalog. Notably, CVE-2021-22005 has been associated with ransomware campaigns. The EPSS score of 94.46% (99.99th percentile) indicates near-certain exploitation activity, making this one of the most actively targeted vulnerabilities in VMware infrastructure.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| vmware | cloud foundation | >= 3.0, < 5.0 |
| vmware | vcenter server | 6.5; 6.7; 7.0 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- http://packetstormsecurity.com/files/164439/VMware-vCenter-Server-Analytics-CEIP-Service-File-Upload.html(Exploit, Third Party Advisory, VDB Entry)
- https://www.vmware.com/security/advisories/VMSA-2021-0020.html(Patch, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22005(US Government Resource)
Weakness Type
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
Path traversal is a vulnerability that occurs when software uses external input to construct a pathname but fails to properly neutralize special elements such as ".." and "/" that can cause the pathname to resolve outside of the intended directory. In CVE-2021-22005, the vCenter Server Analytics service does not properly restrict file upload paths, allowing an attacker to upload malicious files to arbitrary locations on the server, ultimately enabling remote code execution.
Learn more: CWE-22 — Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
Impact Analysis
CVE-2021-22005 carries a CVSS 3.1 score of 9.8 (CRITICAL), reflecting the maximum severity level for infrastructure vulnerabilities. The vulnerability is remotely exploitable over the network with low attack complexity, requires no authentication and no user interaction, making it trivially exploitable by any attacker with network access to port 443. Confidentiality (High): Successful exploitation grants the attacker code execution on the vCenter Server, enabling access to all managed virtual infrastructure credentials, configurations, and data. Integrity (High): An attacker can modify vCenter Server configurations, deploy malicious virtual machines, or tamper with the entire VMware environment. Availability (High): Complete control over the vCenter Server allows an attacker to shut down virtual machines, disrupt services, or deploy ransomware across the managed infrastructure. The EPSS score of 94.46% confirms near-certain exploitation, and the known association with ransomware campaigns makes this vulnerability an immediate priority for remediation.
Exploit Maturity
CVE-2021-22005 is confirmed as actively exploited through its listing in the CISA Known Exploited Vulnerabilities catalog, and it is known to be used in ransomware campaigns. Public exploit code is available via Packet Storm Security, providing attackers with ready-to-use exploit tools. The EPSS score of 94.46% (99.99th percentile) indicates near-certain exploitation activity, placing this among the most actively targeted vulnerabilities. Federal agencies were required to remediate this vulnerability by 2021-11-17 per CISA binding operational directive, reflecting the extreme urgency of this threat.
Remediation
- Apply vendor patches immediately as mandated by CISA KEV: Apply updates per vendor instructions. Refer to VMware Security Advisory VMSA-2021-0020 for the latest patched versions of vCenter Server and Cloud Foundation.
- Verify that all instances of affected products (VMware vCenter Server versions 6.5, 6.7, and 7.0; VMware Cloud Foundation versions 3.x through 5.0) have been updated to patched versions.
- If immediate patching is not possible, restrict network access to port 443 on vCenter Server using firewall rules and network segmentation. Limit access to only trusted management networks and administrators.
- Monitor vCenter Server logs for indicators of compromise, including unusual file upload activity to the Analytics service endpoint, unexpected process execution, and unauthorized configuration changes. Conduct threat hunting for signs of ransomware deployment.
- Implement strict input validation and path canonicalization for all file upload functionality as a long-term hardening measure. Ensure file uploads are restricted to designated directories with proper access controls.
Technical Details
CVE-2021-22005 is an arbitrary file upload vulnerability in the Analytics service of VMware vCenter Server. The vulnerability stems from a path traversal weakness (CWE-22) where the Analytics service fails to properly validate and restrict the destination paths for uploaded files. A malicious actor with network access to port 443 can craft a specially formed file upload request that exploits this path traversal flaw to place files in arbitrary locations on the vCenter Server file system, ultimately achieving remote code execution. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) confirms the maximum exploitability characteristics: network-accessible, low complexity, no authentication, and no user interaction required, with complete impact on confidentiality, integrity, and availability.
Frequently Asked Questions
Is CVE-2021-22005 being actively exploited?
Yes. CVE-2021-22005 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. It is also known to be associated with ransomware campaigns. The EPSS score of 94.46% (99.99th percentile) indicates near-certain exploitation activity.
What products are affected by CVE-2021-22005?
CVE-2021-22005 affects VMware vCenter Server versions 6.5, 6.7, and 7.0, as well as VMware Cloud Foundation versions 3.x through 5.0. Any organization running these versions with network-accessible vCenter Server instances is at risk.
How do I fix CVE-2021-22005?
Apply updates per vendor instructions as detailed in VMware Security Advisory VMSA-2021-0020. If immediate patching is not feasible, restrict network access to port 443 on the vCenter Server and monitor for indicators of compromise.
How severe is CVE-2021-22005?
CVE-2021-22005 has a CVSS 3.1 score of 9.8 (CRITICAL) and is one of the most actively exploited VMware vulnerabilities. Its association with ransomware campaigns and an EPSS score in the 99.99th percentile make it an immediate remediation priority.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.