
Exploit for CVE-2021-21972, a remote code execution vulnerability in VMware vCenter Server via arbitrary file upload on port 443.
cve-2021-21972 is a code execution vulnerability
A malicious attacker with access to port 443 can send a specially crafted request to vCenter Server, ultimately leading to remote arbitrary code execution.
1、The vulnerability is arbitrary file upload
2、The vulnerable interface is
/ui/vropspluginui/rest/services/uploadova,
full path
https://domain.com/ui/vropspluginui/rest/services/uploadova
- Upgrade vCenter Server version 7.0 to 7.0.U1c
- Upgrade vCenter Server version 6.7 to 6.7.U3l
- Upgrade vCenter Server version 6.5 to 6.5 U3n