VMware issues emergency patch for critical security flaws

A man standing in front of a rack of servers inside a data center
(Image credit: Shutterstock.com / Gorodenkoff)

VMware has patched over a dozen vulnerabilities in its flagship products, one of which is a critical file upload vulnerability that can be used to execute commands and software on the vCenter Server appliance.

The critical bug, tracked as CVE-2021-22005, is the third vCenter vulnerability this year that’s rated 9.8/10 in severity, and is part of the 19 that plague VMware’s vCenter, vSphere, and Cloud Foundation product lines.

"A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file," states VMware's advisory.

The vulnerabilities affect vSphere v6.5, Cloud Foundation 3.x and 4.x, vCenter Server 6.7 and 7.0 releases, and the advisory urges users of these versions to patch their instances without delay.

Emergency change

In a blog post about the vulnerabilities, VMware’s technical marketing architect, Bob Plankers points out that users must patch CVE-2021-22005 immediately since it “can be used by anyone who can reach vCenter Server over the network to gain access, regardless of the configuration settings of vCenter Server.”

While VMware’s advisory doesn’t mention if any of the vulnerabilities have been exploited in the wild, recent vCenter flaws, like the vSphere client bug patched earlier this year in May, were. 

Reporting on the development, The Register notes that despite the critical nature of CVE-2021-22005 the company has urged users to look at patching the other flaws as well.

While most of them can’t be exploited remotely, lessening their impact, many of them can be exploited to do considerable damage.

Via The Register

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Security
Broadcom releases fixes for multiple VMware security flaws
A person's fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
Veeam backup software has a serious security flaw - here's how to stay safe
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Representational image depecting cybersecurity protection
Ivanti reveals major security update, so make sure you're protected
vpn
Ivanti warns another critical security flaw is being attacked
Latest in Security
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
Latest in News
EA Sports F1 25 promotional image featuring drivers Oscar Piastri, Carlos Sainz and Oliver Bearman.
F1 25 has been officially announced, with this year's entry marking a return for Braking Point and a 'significant overhaul' for My Team mode
Garmin clippd integration
Garmin's golf watches just got a big software integration upgrade to help you improve your game
Robert Downey Jr reveals himself as Doctor Doom to a delighted crowd at San Diego Comic-Con 2024
Marvel is currently making a major announcement about Avengers: Doomsday's cast on YouTube, and I think it's going to be a long-winded reveal
Samsung QN90F on yellow background
Samsung announces US prices for its 2025 mini-LED TV lineup, and it’s good and bad news
Nintendo Switch Lite
Forget the Nintendo Switch 2, the original Switch is getting one last hurrah in a surprise Nintendo Direct tomorrow
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
Samsung Galaxy S25 Edge colors seemingly revealed in new video, and there’s another sign of an imminent launch