Drop everything and patch VMware’s vCenter Server Vulnerabilities
For a detailed advisory, download the pdf file here.
VMware has issued patches for 19 new vulnerabilities. CVE-2021-22005 is the worst of the lot, defined as “an arbitrary file upload vulnerability in the Analytics service” of the vCenter Server. An attacker with network access to vCenter Server’s port 443 might use this flaw to execute code on the server by uploading a specially crafted file. VMware also provides a temporary workaround for individuals who are unable to instantly patch their appliances.
Vulnerability Details
Patch Link
https://www.vmware.com/security/advisories/VMSA-2021-0020.html
References
https://blogs.vmware.com/vsphere/2021/09/vmsa-2021-0020-what-you-need-to-know.html
https://www.theregister.com/2021/09/22/vmware_emergency_vcenter_patch_recommendation/
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox