Published on: 24 February 2021
Last update on: 26 February 2021
VMware has published a security advisory to address multiple vulnerabilities in VMware products. The list of security updates can be found at:
https://www.vmware.com/security/advisories/VMSA-2021-0002.html
The proof-of-concept exploit code for the remote code execution (RCE) vulnerability (CVE-2021-21972) in VMware vCenter server has been publicly available on the Internet. Active scannings for Internet-accessible vulnerable vCenter servers have been observed. System administrators are advised to take immediate actions to patch your affected systems to mitigate the elevated risk of cyber attacks. It is advised not to expose VMware vCenter servers to the Internet if not necessary.
Depending on the vulnerabilities being exploited, a successful exploitation of the vulnerabilities could result in command execution with unrestricted privileges, remote code execution and information disclosure on the affected system.
Patches for affected products are available. System administrators of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.