CISA Known Exploited Vulnerability

CVE-2021-21985 Ransomware

VMware · vCenter Server

VMware vCenter Server Improper Input Validation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-20, CWE-470, CWE-918
Ransomware Known

CISA description

VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.

Required action

Apply updates per vendor instructions.