vSphere Unauthenticated Remote Code Execution Vulnerability – VMSA-2021-0002
For vendor guidance please see:
https://www.vmware.com/security/advisories/VMSA-2021-0002.html
CVE Refs: CVE-2021-21972, CVE-2021-21973, CVE-2021-21974
Introduction
There’s a new unauthenticated remove code execution (RCE) in vSphere 6.5, 6.7 and 7.0 which has just dropped. There’s a vendor patch and currently there is no known public exploit however the hunt will now be on and I can imagine that it’s hours and days until this is in the wild rather than weeks or months.
Read more “vSphere Unauthenticated Remote Code Execution Vulnerability – VMSA-2021-0002”