Hackers have begun scanning for vulnerable VMware vCenter servers

An abstract image of padlocks overlaying a digital background.
(Image credit: Shutterstock)

In a not entirely unexpected development, threat actors have started looking for internet-exposed VMware vCenter servers whose admins haven’t yet patched them against the critical arbitrary file upload vulnerability that was disclosed yesterday.

The critical security flaw, tracked as CVE-2021-22005 impacts VMware’s flagship vCenter Server deployments, and could help facilitate remote code execution (RCE) attacks from unauthenticated attackers without requiring user interaction.

“In this era of ransomware it is safest to assume that an attacker is already inside your network somewhere, on a desktop and perhaps even in control of a user account, which is why we strongly recommend declaring an emergency change and patching as soon as possible," warned Bob Plankers, Technical Marketing Architect at VMware yesterday as he urged vCenter Server admins to apply the patches without delay.

It seems the threat actors were more attentive, and it wasn’t long until the honeypots of threat intelligence company Bad Packets were scanned by malicious users looking for unpatched vCenter Servers.

Just a matter of time

Bad Packets later added that the malicious scans of its honeypots revealed that they were based on the workaround information provided by VMware for customers who couldn't immediately patch their appliances.

Sharing the development, BleepingComputer points out that this isn’t the first time threat actors have taken advantage of an admin’s laxity in patching their vCenter Servers to scan for and attack them soon after a vulnerability is disclosed.

In fact, there have been a couple of similar incidents this year alone, first in February (based on (based on CVE-2021-21972), and then in May (based on CVE-2021-21985).

The only saving grace with CVE-2021-22005, at least for now, is that unlike the previously mentioned vulnerabilities, security researchers haven’t yet caught hold of any exploit code that could capitalize on the bug. 

However, since threat actors are actively scanning for vulnerable servers, chances are they already have a working exploit, or one that’s close to completion. In either case, the activity should be enough to convince admins to drop everything and patch their exposed vCenter Servers immediately.

Via BleepingComputer

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
A person holding out their hand with a digital AI symbol.
This ransomware gang is using SSH tunnels to target VMware appliances
A person's fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
Veeam backup software has a serious security flaw - here's how to stay safe
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
A VPN runs on a mobile phone placed on a laptop keyboard
SonicWall firewalls hit by worrying cyberattack
Security
Broadcom releases fixes for multiple VMware security flaws
vpn
Ivanti warns another critical security flaw is being attacked
Latest in Security
person at a computer
Many workers are overconfident at spotting phishing attacks
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Latest in News
A man getting angry with his laptop.
Windows 11 bug deletes Copilot from the OS – is this the first glitch ever some users will be happy to encounter?
Huawei Watch Fit 3
The Huawei Watch 3 is a decent Apple Watch alternative, and its successor could be close at hand
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung's latest software upgrade could mean Galaxy phones beat iPhones for gaming – but you can't get it yet
God of War 20th Anniversary Graphic.
Sony has unveiled some goodies to celebrate God of War’s 20th anniversary, but it's not the remaster I was hoping for
person at a computer
Many workers are overconfident at spotting phishing attacks
Apple iPhone 16 Plus Review
The iPhone 17 Air could have an affordable price, and better battery life than you might have expected