CVE-2021-21972

9.8
CRITICALCVSS v3.1 Base Score
99.87%
HIGH RiskEPSS (100th percentile)
KEV

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

Published: 2/24/2021
Modified: 8/12/2026
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

VMware vCenter Server Remote Code Execution Vulnerability

Vendor / Product:

VMware vCenter Server

Required Action:

Apply updates per vendor instructions.

Due Date: 11/17/2021(OVERDUE)
Ransomware Campaign Use
Added to KEV:

11/3/2021

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2021-21972

Vulnerability Summary

CVSS v3 Score

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

10

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

99.87%HIGH Exploitation Risk
100th percentile

This vulnerability has a 99.87% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

CWE Classification

Advertisement