VMware Issues Urgent Warning About Critical File Upload Vulnerability in vCenter Server
On September 22, 2021, VMware released a bulletin detailing up to 19 vulnerabilities in vCenter Server and Cloud Foundation appliances that could be exploited by remote attackers to gain control of affected systems. The most pressing concern is an arbitrary file upload vulnerability in the Analytics service (CVE-2021-22005), which affects vCenter Server versions 6.7 and 7.0. According to VMware, “A malicious actor with network access to port 443 on vCenter Server could exploit this issue to execute code by uploading a specially crafted file.” The company emphasized that this vulnerability is accessible to anyone who can reach vCenter Server over the network, irrespective of its configuration settings. While VMware has provided temporary workarounds for this issue, they caution that these measures are intended only as a stopgap until proper updates can be deployed.
VMware Issues Urgent Advisory on Critical File Upload Vulnerability in vCenter Server On September 22, 2021, VMware issued a critical alert highlighting the discovery of 19 vulnerabilities within its vCenter Server and Cloud Foundation appliances. These vulnerabilities pose significant risks,…