{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3avmwarevcenter_server6.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vmware:vcenter_server:6.5:*:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:6.7:*:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:*:*:*:*:*:*:*","cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2021-21985"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["vCenter Server (6.5, 6.7, 7.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","vmware"],"_cs_type":"advisory","_cs_vendors":["VMware"],"content_html":"\u003cp\u003eCVE-2021-21985 is a critical remote code execution (RCE) vulnerability affecting the vSphere Client (HTML5) in VMware vCenter Server versions 6.5, 6.7, and 7.0. The vulnerability is caused by an input validation flaw within the Virtual SAN Health Check plug-in, which is enabled by default. As of October 2026, multiple proof-of-concept (PoC) exploits have been published on security platforms, significantly lowering the barrier for exploitation. An unauthenticated attacker can send specially crafted HTTP POST requests to the vCenter server to trigger arbitrary code execution via JNDI lookup or other VMODL helper operations. This vulnerability is highly dangerous due to its remote, unauthenticated nature and CVSS score of 10.0, allowing complete system compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker performs initial reconnaissance to identify internet-facing vCenter instances.\u003c/li\u003e\n\u003cli\u003eThe attacker sends an HTTP POST request to '/ui/h5-vsan/rest/proxy/service/\u0026amp;vsanProviderUtils_setVmodlHelper/setTargetObject' to set the target object to null.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a request to '/ui/h5-vsan/rest/proxy/service/\u0026amp;vsanProviderUtils_setVmodlHelper/setStaticMethod' with 'javax.naming.InitialContext.doLookup' as the payload.\u003c/li\u003e\n\u003cli\u003eThe attacker configures the target method by sending a POST request to '/ui/h5-vsan/rest/proxy/service/\u0026amp;vsanProviderUtils_setVmodlHelper/setTargetMethod' with 'doLookup'.\u003c/li\u003e\n\u003cli\u003eThe attacker specifies the JNDI payload, such as 'rmi://attacker-controlled-server:9090/resource', via a POST request to '/ui/h5-vsan/rest/proxy/service/\u0026amp;vsanProviderUtils_setVmodlHelper/setArguments'.\u003c/li\u003e\n\u003cli\u003eThe attacker initializes the helper class by sending a POST request to the 'prepare' endpoint.\u003c/li\u003e\n\u003cli\u003eThe attacker triggers the final payload execution by sending a POST request to the 'invoke' endpoint.\u003c/li\u003e\n\u003cli\u003eThe vCenter server initiates an outbound connection to the attacker's infrastructure, resulting in code execution or data exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker to gain full control over the vCenter Server. This impact includes complete loss of confidentiality, integrity, and availability for the vCenter instance and all virtual machines managed by it. Given the prevalence of vCenter in enterprise environments, successful exploitation could facilitate widespread ransomware distribution or persistent lateral movement within an organization's internal network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch all instances of VMware vCenter Server to the latest version as recommended in VMSA-2021-0010.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to monitor for unauthorized usage of the 'vsanProviderUtils_setVmodlHelper' service.\u003c/li\u003e\n\u003cli\u003eMonitor firewall and proxy logs for unusual outbound connections originating from vCenter Servers, specifically RMI or LDAP traffic (TCP/9090 or others).\u003c/li\u003e\n\u003cli\u003eEnable detailed logging for the vSphere Client ('/var/log/vmware/vsphere-ui/logs/vsphere_client_virgo.log') and audit for the specific endpoints described in the attack chain.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T01:30:33Z","date_published":"2026-10-07T01:30:33Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2021-21985-vcenter-rce/","summary":"Public proof-of-concept exploits for CVE-2021-21985 have been released, enabling unauthenticated remote code execution in VMware vCenter Server via the Virtual SAN Health Check plug-in.","title":"Exploitation of CVE-2021-21985 in VMware vCenter Server","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2021-21985-vcenter-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:vmware:vcenter_server:6.5:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}