CVE-2021-22015

HIGH

Vmware Cloud Foundation < 5.0 - Privilege Escalation

Title source: rule
STIX 2.1

Description

The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their privileges to root on vCenter Server Appliance.

Exploits (2)

nomisec SCANNER 6 stars
by PenteraIO · poc
https://github.com/PenteraIO/vScalation-CVE-2021-22015
metasploit WORKING POC MANUAL
by h00die, Yuval Lazar · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/vcenter_java_wrapper_vmon_priv_esc.rb

Scores

CVSS v3 7.8
EPSS 0.0179
EPSS Percentile 82.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-552
Status published
Products (4)
vmware/cloud_foundation 3.0 - 5.0
vmware/vcenter_server 6.5
vmware/vcenter_server 6.7
vmware/vcenter_server 7.0
Published Sep 23, 2021
Tracked Since Feb 18, 2026