CVE-2021-21974

HIGH EXPLOITED IN THE WILD RANSOMWARE

Vmware Esxi < 3.10.1.2 - Out-of-Bounds Write

Title source: rule

Description

OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.

Exploits (7)

nomisec WORKING POC 186 stars
by Shadow0ps · remote
https://github.com/Shadow0ps/CVE-2021-21974
nomisec SCANNER 2 stars
by CYBERTHREATANALYSIS · poc
https://github.com/CYBERTHREATANALYSIS/ESXi-Ransomware-Scanner-mi
nomisec SCANNER 2 stars
by n2x4 · poc
https://github.com/n2x4/Feb2023-CVE-2021-21974-OSINT
nomisec SCANNER
by abirasecurity · poc
https://github.com/abirasecurity/CVE-2021-21974_vuln_dectection
nomisec WORKING POC
by mercylessghost · remote
https://github.com/mercylessghost/CVE-2021-21974
nomisec NO CODE
by hateme021202 · poc
https://github.com/hateme021202/cve-2021-21974
vulncheck_xdb WORKING POC
remote
https://github.com/OUB3LL4/vmware_esxi_exp

Scores

CVSS v3 8.8
EPSS 0.5570
EPSS Percentile 98.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-02-03
InTheWild.io 2023-02-03
Ransomware Use Confirmed
CWE
CWE-787
Status published
Products (2)
vmware/cloud_foundation 3.0 - 3.10.1.2
vmware/esxi 6.5 (49 CPE variants)
Published Feb 24, 2021
Tracked Since Feb 18, 2026