CVE-2021-22005

CRITICAL(9.8)KEVRansomwareLikely Exploited

VMware vCenter Server File Upload Vulnerability

Description

CVE-2021-22005 is a critical arbitrary file upload vulnerability in VMware vCenter Server that allows a malicious actor with network access to port 443 to execute code on the server by uploading a specially crafted file to the Analytics service. This VMware vCenter Server vulnerability has a CVSS 3.1 score of 9.8 (CRITICAL) and has been actively exploited in the wild, as confirmed by its inclusion in the CISA Known Exploited Vulnerabilities catalog. Notably, CVE-2021-22005 has been associated with ransomware campaigns. The EPSS score of 94.46% (99.99th percentile) indicates near-certain exploitation activity, making this one of the most actively targeted vulnerabilities in VMware infrastructure.

KEV Information

Vendor
VMware
Product
vCenter Server
Date Added
November 3, 2021
Due Date
November 17, 2021
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
vmwarecloud foundation>= 3.0, < 5.0
vmwarevcenter server6.5; 6.7; 7.0

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)

Path traversal is a vulnerability that occurs when software uses external input to construct a pathname but fails to properly neutralize special elements such as ".." and "/" that can cause the pathname to resolve outside of the intended directory. In CVE-2021-22005, the vCenter Server Analytics service does not properly restrict file upload paths, allowing an attacker to upload malicious files to arbitrary locations on the server, ultimately enabling remote code execution.

Learn more: CWE-22 — Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)

Impact Analysis

CVE-2021-22005 carries a CVSS 3.1 score of 9.8 (CRITICAL), reflecting the maximum severity level for infrastructure vulnerabilities. The vulnerability is remotely exploitable over the network with low attack complexity, requires no authentication and no user interaction, making it trivially exploitable by any attacker with network access to port 443. Confidentiality (High): Successful exploitation grants the attacker code execution on the vCenter Server, enabling access to all managed virtual infrastructure credentials, configurations, and data. Integrity (High): An attacker can modify vCenter Server configurations, deploy malicious virtual machines, or tamper with the entire VMware environment. Availability (High): Complete control over the vCenter Server allows an attacker to shut down virtual machines, disrupt services, or deploy ransomware across the managed infrastructure. The EPSS score of 94.46% confirms near-certain exploitation, and the known association with ransomware campaigns makes this vulnerability an immediate priority for remediation.

Exploit Maturity

CVE-2021-22005 is confirmed as actively exploited through its listing in the CISA Known Exploited Vulnerabilities catalog, and it is known to be used in ransomware campaigns. Public exploit code is available via Packet Storm Security, providing attackers with ready-to-use exploit tools. The EPSS score of 94.46% (99.99th percentile) indicates near-certain exploitation activity, placing this among the most actively targeted vulnerabilities. Federal agencies were required to remediate this vulnerability by 2021-11-17 per CISA binding operational directive, reflecting the extreme urgency of this threat.

Remediation

  1. Apply vendor patches immediately as mandated by CISA KEV: Apply updates per vendor instructions. Refer to VMware Security Advisory VMSA-2021-0020 for the latest patched versions of vCenter Server and Cloud Foundation.
  2. Verify that all instances of affected products (VMware vCenter Server versions 6.5, 6.7, and 7.0; VMware Cloud Foundation versions 3.x through 5.0) have been updated to patched versions.
  3. If immediate patching is not possible, restrict network access to port 443 on vCenter Server using firewall rules and network segmentation. Limit access to only trusted management networks and administrators.
  4. Monitor vCenter Server logs for indicators of compromise, including unusual file upload activity to the Analytics service endpoint, unexpected process execution, and unauthorized configuration changes. Conduct threat hunting for signs of ransomware deployment.
  5. Implement strict input validation and path canonicalization for all file upload functionality as a long-term hardening measure. Ensure file uploads are restricted to designated directories with proper access controls.

Technical Details

CVE-2021-22005 is an arbitrary file upload vulnerability in the Analytics service of VMware vCenter Server. The vulnerability stems from a path traversal weakness (CWE-22) where the Analytics service fails to properly validate and restrict the destination paths for uploaded files. A malicious actor with network access to port 443 can craft a specially formed file upload request that exploits this path traversal flaw to place files in arbitrary locations on the vCenter Server file system, ultimately achieving remote code execution. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) confirms the maximum exploitability characteristics: network-accessible, low complexity, no authentication, and no user interaction required, with complete impact on confidentiality, integrity, and availability.

Frequently Asked Questions

Is CVE-2021-22005 being actively exploited?

Yes. CVE-2021-22005 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. It is also known to be associated with ransomware campaigns. The EPSS score of 94.46% (99.99th percentile) indicates near-certain exploitation activity.

What products are affected by CVE-2021-22005?

CVE-2021-22005 affects VMware vCenter Server versions 6.5, 6.7, and 7.0, as well as VMware Cloud Foundation versions 3.x through 5.0. Any organization running these versions with network-accessible vCenter Server instances is at risk.

How do I fix CVE-2021-22005?

Apply updates per vendor instructions as detailed in VMware Security Advisory VMSA-2021-0020. If immediate patching is not feasible, restrict network access to port 443 on the vCenter Server and monitor for indicators of compromise.

How severe is CVE-2021-22005?

CVE-2021-22005 has a CVSS 3.1 score of 9.8 (CRITICAL) and is one of the most actively exploited VMware vulnerabilities. Its association with ransomware campaigns and an EPSS score in the 99.99th percentile make it an immediate remediation priority.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score100.00%
EPSS Percentile100.0%

Dates

PublishedSeptember 23, 2021
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.