---
id: CVE-2021-21972
title: >-
  The vSphere Client (HTML5) contains a remote code execution vulnerability in a
  vCenter Server plugin
summary: >-
  The vSphere Client (HTML5) contains a remote code execution vulnerability in a
  vCenter Server plugin. A malicious actor with network access to port 443 may
  exploit this issue to execute commands with unrestricted privileges on the
  underl…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
  - CWE-22
vendor: vmware
product: cloud_foundation
affected:
  - 'cloud_foundation >= 3.0, < 3.10.1.2'
  - 'cloud_foundation >= 4.0, < 4.2'
  - vcenter_server = 6.5
  - vcenter_server = 6.7
  - vcenter_server = 7.0
patched:
  - cloud_foundation 4.2
published: '2021-02-24'
updated: '2026-08-12'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-21972'
references:
  - url: >-
      http://packetstormsecurity.com/files/161590/VMware-vCenter-Server-7.0-Arbitrary-File-Upload.html
    label: security@vmware.com
  - url: >-
      http://packetstormsecurity.com/files/161695/VMware-vCenter-Server-File-Upload-Remote-Code-Execution.html
    label: security@vmware.com
  - url: >-
      http://packetstormsecurity.com/files/163268/VMware-vCenter-6.5-6.7-7.0-Remote-Code-Execution.html
    label: security@vmware.com
  - url: 'https://www.vmware.com/security/advisories/VMSA-2021-0002.html'
    label: security@vmware.com
  - url: >-
      http://packetstormsecurity.com/files/161590/VMware-vCenter-Server-7.0-Arbitrary-File-Upload.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/161695/VMware-vCenter-Server-File-Upload-Remote-Code-Execution.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/163268/VMware-vCenter-6.5-6.7-7.0-Remote-Code-Execution.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.vmware.com/security/advisories/VMSA-2021-0002.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21972
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.99865
epssPercentile: 0.99962
kev: true
kevDateAdded: '2021-11-03'
kevDueDate: '2021-11-17'
kevRansomware: true
exploited: true
exploitAvailable: true
zeroDay: true
ingestedAt: '2026-08-12T19:54:25.573Z'
exploits:
  exploitdb: true
  github: 27
  githubRepos:
    - 'https://github.com/psc4re/NSE-scripts'
    - 'https://github.com/QmF0c3UK/CVE-2021-21972-vCenter-6.5-7.0-RCE-POC'
    - 'https://github.com/NS-Sp4ce/CVE-2021-21972'
  metasploit:
    - exploit/multi/http/vmware_vcenter_uploadova_rce
  nuclei:
    - CVE-2021-21972
  checkedAt: '2026-09-10T03:03:48.863Z'
---

## Overview

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

## Affected

- `cloud_foundation >= 3.0, < 3.10.1.2`
- `cloud_foundation >= 4.0, < 4.2`
- `vcenter_server = 6.5`
- `vcenter_server = 6.7`
- `vcenter_server = 7.0`

## Remediation

Upgrade past the affected range:

- `cloud_foundation 4.2`
