FortiGuard Labs is aware that VMware disclosed a critical vulnerability (CVE-2021-22005) on September 21st, 2021 that affects vCenter Server versions 6.7 and 7.0. A malicious attacker with network access to port 443 on vCenter Server can exploit the vulnerability and can execute code on vCenter Server upon successful exploitation. The VMware advisory was updated on September 24th that the vulnerability is being exploited in the wild. In addition, exploit code is publicly available.
Why is this Significant?
VMware has one of the highest market shares in the server virtualization market so the vulnerability can have widespread affect. Also, some public reports indicate that CVE-2021-22005 is being exploited in the wild. With exploit code being publicly available, more attackers are expected to leverage the security bug. Because of the potential impact the vulnerability has in the field, CISA released an advisory on September 24th, 2021.
What are the Details of the Vulnerability?
Details of the vulnerability have not been disclosed by VMware.
Has VMware Released an Advisory for CVE-2021-22005?
Yes, the vendor released a cumulative advisory on September 21st, 2021. See the Appendix for a link to VMSA-2021-0020.1. The vendor also released a supplemental blog post and an advisory. See the Appendix to a link to "VMSA-2021-0020: What You Need to Know" and "VMSA-2021-0020: Questions & Answers".
Has the Vendor Released a Patch?
Yes. VMware released a patch on September 21st, 2021.
Any Mitigation and or Workarounds?
VMware provided workarounds in a blog. See the Appendix to a link to "Workaround Instructions for CVE-2021-22005 (85717)".
What is The Status of Coverage?
FortiGuard Labs provides the following IPS signature:
VMSA-2021-0020: Questions & Answers (VMware)