⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2021-21974Out-of-bounds Write in Vmware Esxi

CWE-787Out-of-bounds Write12 documents10 sources
Severity
8.8HIGHNVD
EPSS
55.7%
top 1.91%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedFeb 24
Latest updateFeb 7

Description

OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

NVDvmware/esxi6.5, 6.7, 7.0.0+2
CVEListV5vmware/vmware_esxi6.5 before ESXi650-202102101-SG, 6.7 before ESXi670-202102401-SG, 7.0 before ESXi70U1c-17325551+2
NVDvmware/cloud_foundation3.03.10.1.2+1
CVEListV5vmware/vmware_cloud_foundation4.x before 4.2 and 3.x

🔴Vulnerability Details

3
GHSA
GHSA-4mwc-fv8c-wp9f: OpenSLP as used in ESXi (72022-05-24
CVEList
CVE-2021-21974: OpenSLP as used in ESXi (72021-02-24
VulnCheck
VMware cloud_foundation Out-of-bounds Write2021

🔍Detection Rules

1
Suricata
ET EXPLOIT VMWare ESXi 6.7.0 OpenSLP Remote Code Execution Attempt - Directory Agent Advertisement Heap Overflow (CVE-2021-21974)2023-02-03

📋Vendor Advisories

2
Red Hat
OpenSLP: heap-overflow2021-02-24
VMware
VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2021-21972, CVE-2021-21973, CVE-2021-21974)2021-02-23

🕵️Threat Intelligence

5
Wiz
Ransomware attacks targeting VMware ESXi servers | Wiz Blog2023-02-07
Wiz
Ransomware attacks targeting VMware ESXi servers | Wiz Blog2023-02-07
Recorded Future
ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers
Recorded Future
ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers | Recorded Future
Huntress
VMware ESXi Vulnerability: Analysis, Impact, Mitigation | Huntress
CVE-2021-21974 — Out-of-bounds Write in Vmware Esxi | cvebase