CVE-2021-21972
VMware vCenter Server Remote Code Execution Vulnerability
- Published
- Feb 24, 2021
- Updated
- Aug 12, 2026
- Assigning CNA
- vmware
- Evidence observed
- Mar 1, 2021
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 100.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
Sources
29- CVE-2021-21972Scanner
Nmap script to detect VMware vCenter Server CVE-2021-21972 RCE vulnerability by probing the uploadova endpoint and checking for vulnerable response.
- CVE-2021-21972Scanner
VMware vCenter Server远程代码执行漏洞 (CVE-2021-21972)批量检测脚本
- CVE-2021-21972Scanner
Nmap script to check vulnerability CVE-2021-21972
- CVE-2021-21972Exploit
Proof of Concept Exploit for vCenter CVE-2021-21972
- CVE-2021-21972Research
Isolated lab research writeup for VMware vCenter Server CVE-2021-21972, covering unauthenticated arbitrary file upload to RCE, Nmap-based detection, exploitation chain, and mitigations.
- Detect-CVE-2021-21972Scanner
Lightweight Python scanner to detect CVE-2021-21972 VMware vCenter vulnerability with automated exploitation checks for penetration testing.
- vcenter_rceExploit
Exploit, Vmware vCenter 6.5-7.0 RCE (CVE-2021-21972), upload Behinder 3, getshell
- CVE-2021-21972Exploit
CVE-2021-21972
- CVE-2021-21972Exploit
[CVE-2021-21972] VMware vSphere Client Unauthorized File Upload to Remote Code Execution (RCE)
- CVE-2021-21972Exploit
CVE-2021-21972 – ᴠᴍᴡᴀʀᴇ ᴄʟɪᴇɴᴛ ᴜɴᴀᴜᴛʜᴏʀɪᴢᴇᴅ ᴄᴏᴅᴇ ɪɴᴊᴇᴄᴛɪᴏɴ (ʀᴄᴇ)
- vSphereyeeterExploit
POC exploit for CVE-2021-21972
Proof-of-concept for CVE-2021-21972, a remote code execution vulnerability in vCenter Server 6.5-7.0. Verifies vulnerable paths without exploitation.
VMware vCenter CVE-2021-21972 Tools
- CVE-2021-21972Exploit
Exploit for CVE-2021-21972, a remote code execution vulnerability in VMware vCenter Server via arbitrary file upload on port 443.
- CVE-2021-21972Exploit
CVE-2021-21972 Unauthorized RCE in VMware vCenter metasploit exploit script
Python-based exploit and detection script for CVE-2021-21972 (VMware vCenter unauthorized RCE), using Zoomeye dork for host discovery and pocsuite3 for harmless scanning.
- cve-2021-21972Exploit
Python-based proof-of-concept exploit for CVE-2021-21972 targeting VMware vCenter with webshell and SSH payload delivery for Linux systems.
- CVE-2021-21972Exploit
Exploit for CVE-2021-21972 targeting VMware vCenter Server, enabling remote code execution via the vSphere Client.
- CVE-2021-21972Exploit
Exploit for CVE-2021-21972 targeting VMware vCenter with options for webshell or SSH key upload, proxy support, and batch scanning.
- CVE-2021-21972Exploit
CVE-2021-21972 Exploit
A vulnerability scanner that detects CVE-2021-21972 vulnerabilities.
- CVE-2021-21972Exploit
CVE-2021-21972
- VcenterKillerExploit
一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webshell,命令执行或者上传公钥使用SSH免密连接
- CTT-enhanced-VMware-vCenterExploit
Looking at current high-impact vulnerabilities, let's use the VMware vCenter Server CVE-2021-21972 (CVSS 9.8) as our base. This is a publicly known RCE with patches available, perfect for demonstrating CTT enhancements.
CVE-2021-21972 vCenter-6.5-7.0 RCE POC
Collection of Proof-of-Concept exploits for VMware vCenter vulnerabilities enabling RCE, SSRF, and arbitrary file read. Includes Shodan query for target discovery.
- CVE-2021-21972Exploit
CVE-2021-21972 related vulnerability code
Photubias · multiple · Mar 1, 2021
CHackA0101 · multiple · Jun 24, 2021
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.