CVE-2021-22015
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 1.9%
from disclosure to weapon0 days
Published on NVDSep 23
metasploitSep 21
exploitation probability
1.9%top 21% of all CVEs
observed exploitation
nono source reports it
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their privileges to root on vCenter Server Appliance.
Affected products
n/a · VMware vCenter Server, VMware Cloud Foundation