CVE-2021-21974
published 2021-02-24CVE-2021-21974: OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A…
PriorityP189high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVRansomwareInitial access
Exploited in the wild
EPSS
45.06%
98.6th percentile
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | >= 3.0 < 3.10.1.2 | 3.10.1.2 |
| vmware | cloud_foundation | >= 4.0 < 4.2 | 4.2 |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for presence of ESXiArgs ransomware dropper files in /tmp: 'encrypt', 'encrypt.sh', and 'public.pem' — their presence is a confirmed post-exploitation IOC. ↗
- →Alert on inbound TCP/UDP connections to port 427 (OpenSLP) from untrusted or external sources on ESXi hosts, as this is the attack entry point for CVE-2021-21974. ↗
- →Detect ransomware activity by monitoring for mass termination of VMX processes (VM shutdown attempts) followed by encryption of .vmdk, .vmx, .vmxf, .vmsd, .vmsn, .vswp, .vmss, .nvram, and .vmem files. ↗
- →Check Point IPS signature available for detection: 'VMWare OpenSLP Heap Buffer Overflow (CVE-2019-5544; CVE-2021-21974)'. ↗
- →Detect creation of 'argsfile' on ESXi hosts, used by the malware to store encryption parameters (MB to skip, MB per encryption block, file size). ↗
- →CERT-FR notes that encrypted .vmdk files may be renamed with a .args extension — monitor for this file extension change as a ransomware indicator. ↗
- ·CVE-2021-21974 is not yet officially confirmed as the sole attack vector; CVE-2020-3992 (also an OpenSLP vulnerability) has been listed by French CERT as another possibility. ↗
- ·The OpenSLP service (port 427) is disabled by default on new ESXi installations since ESXi 7.0 U2c and ESXi 8.0 GA — exploitation requires the service to be running and port 427 reachable. ↗
- ·The VM shutdown step (killing VMX process) used by the ransomware to unlock files before encryption is not reliably successful, which may leave files locked and unencrypted — reducing actual encryption impact in some cases. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:P
vulncheck8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
VMware ESXi OpenSLP heap-based overflow (VMSA-2021-0002)
vuldb·2026-06-03·CVSS 8.8
CVE-2021-21974 [HIGH] VMware ESXi OpenSLP heap-based overflow (VMSA-2021-0002)
A vulnerability described as critical has been identified in VMware ESXi. Affected is an unknown function of the component OpenSLP. Such manipulation leads to heap-based buffer overflow.
This vulnerability is listed as CVE-2021-21974. The attack may be performed from remote. In addition, an exploit is available.
A patch should be applied to remediate this issue.
GHSA
GHSA-4mwc-fv8c-wp9f: OpenSLP as used in ESXi (7
ghsa_unreviewed·2022-05-24
CVE-2021-21974 [HIGH] CWE-787 GHSA-4mwc-fv8c-wp9f: OpenSLP as used in ESXi (7
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.
VulnCheck
VMware cloud_foundation Out-of-bounds Write
vulncheck·2021·CVSS 8.8
CVE-2021-21974 [HIGH] VMware cloud_foundation Out-of-bounds Write
VMware cloud_foundation Out-of-bounds Write
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.
Affected: VMware cloud_foundation
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.cert.ssi.gouv.fr/alerte/CERTFR-2023-ALE-015/; https://www.wiz.io/blog/ransomware-attacks-targeting-vmware-esxi-servers-everything-you-
Red Hat
OpenSLP: heap-overflow
vendor_redhat·2021-02-24·CVSS 8.8
CVE-2021-21974 [HIGH] CWE-787 OpenSLP: heap-overflow
OpenSLP: heap-overflow
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.
A heap overflow vulnerability was found in OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG). This flaw allows a malicious actor residing within the same network segment as ESXi, who has access to port 427, to trigger the heap overflow issue in the OpenSLP service, resulting in remote code execution.
Statement: This vulnerability only exists in VM
VMware
VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2021-21972, CVE-2021-21973, CVE-2021-21974)
vendor_vmware·2021-02-23·CVSS 9.8
CVE-2021-21972 [CRITICAL] VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2021-21972, CVE-2021-21973, CVE-2021-21974)
VMSA-2021-0002: VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2021-21972, CVE-2021-21973, CVE-2021-21974)
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVEs: CVE-2021-21972, CVE-2021-21973, CVE-2021-21974
Affected products: VMware Cloud Foundation, VMware ESXi, VMware vCenter Server, VMware vSphere
Suricata
ET EXPLOIT VMWare ESXi 6.7.0 OpenSLP Remote Code Execution Attempt - Directory Agent Advertisement Heap Overflow (CVE-2021-21974)
suricata·2023-02-03·CVSS 8.8
CVE-2021-21974 [HIGH] ET EXPLOIT VMWare ESXi 6.7.0 OpenSLP Remote Code Execution Attempt - Directory Agent Advertisement Heap Overflow (CVE-2021-21974)
ET EXPLOIT VMWare ESXi 6.7.0 OpenSLP Remote Code Execution Attempt - Directory Agent Advertisement Heap Overflow (CVE-2021-21974)
Rule: alert tcp any any -> $HOME_NET 427 (msg:"ET EXPLOIT VMWare ESXi 6.7.0 OpenSLP Remote Code Execution Attempt - Directory Agent Advertisement Heap Overflow (CVE-2021-21974)"; flow:established,to_server; dsize:>280; content:"|02 08|"; startswith; byte_jump:2,19,relative,little; byte_test:2,>=,256,0,relative; content:"|01|:/"; reference:url,straightblast.medium.com/my-poc-walkthrough-for-cve-2021-21974-a266bcad14b9; reference:cve,2021-21974; classtype:attempted-admin; sid:2044114; rev:1; metadata:affected_product VMware, attack_target Server, created_at 2023_02_03, cve CVE_2021_21974, deployment Perimeter, deployment Internal, deployment Datacenter, performan
No public exploits indexed.
Wiz
Containers vs Virtual Machines (VMs): See the Difference | Wiz
blogs_wiz·2025-04-09
Containers vs Virtual Machines (VMs): See the Difference | Wiz
Containers are lightweight, isolated environments that share the host OS's kernel, supporting faster startup and lower overhead. Virtual machines, on the other hand, emulate entire physical systems, each running its full operating system, which makes them more resource-intensive.
Thanks to VM technology and containers today, you can isolate applications throughout your cloud infrastructure for improved security. Learn the distinctions between containers and VMs and examine their roles in resource isolation, efficiency, and security within digital environments.
Before diving into containers and VMS, here’s an overview of how these choices can determine your infrastructure:
FeatureContainersVMsOS virtualizationShare host OS kernelFull OS virtualization (guest OS per VM)Resource usageLight
Wiz
Containers vs Virtual Machines (VMs): See the Difference | Wiz
blogs_wiz·2025-04-09
Containers vs Virtual Machines (VMs): See the Difference | Wiz
Containers are lightweight, isolated environments that share the host OS's kernel, supporting faster startup and lower overhead. Virtual machines, on the other hand, emulate entire physical systems, each running its full operating system, which makes them more resource-intensive.
Thanks to VM technology and containers today, you can isolate applications throughout your cloud infrastructure for improved security. Learn the distinctions between containers and VMs and examine their roles in resource isolation, efficiency, and security within digital environments.
Before diving into containers and VMS, here’s an overview of how these choices can determine your infrastructure:
OS virtualization
Share host OS kernel
Full OS virtualization (guest OS per VM)
Resource usage
Lightweight (mini
Unit42
Ransomware Retrospective 2024: Unit 42 Leak Site Analysis
blogs_unit42·2024-02-05
Ransomware Retrospective 2024: Unit 42 Leak Site Analysis
## Executive Summary
The ransomware landscape experienced significant transformations and challenges in 2023. The year saw a 49% increase in victims reported by ransomware leak sites, with a total of 3,998 posts from various ransomware groups.
What drove this surge of activity? 2023 saw high-profile vulnerabilities like SQL injection for MOVEit and GoAnywhere MFT services. Zero-day exploits for these vulnerabilities drove spikes in ransomware infections by groups like CL0P, LockBit and ALPHV (BlackCat) before defenders could update the vulnerable software.
Leak site data reveals at least 25 new ransomware groups emerged in 2023, indicating the continued attraction of ransomware as a profitable criminal activity. Despite the appearance of new groups such as Darkrace, CryptNet and U-Bomb,
Unit42
Ransomware Retrospective 2024: Unit 42 Leak Site Analysis
blogs_unit42·2024-02-05
Ransomware Retrospective 2024: Unit 42 Leak Site Analysis
Threat Research Center
Threat Research
Ransomware
## Ransomware Retrospective 2024: Unit 42 Leak Site Analysis
Doel Santos
Published: February 5, 2024
Cybercrime
Ransomware
Threat Research
Trend Reports
ALPHV
Ambitious Scorpius
Blackcat
Buzzing Scorpius
Hive
Ignoble Scorpius
Leak site
Ragnar Locker
Ransomed
Ransomed.Vc
Royal Ransomware
Salty Scorpius
Trigona
Vice Society
## Executive Summary
The ransomware landscape experienced significant transformations and challenges in 2023. The year saw a 49% increase in victims reported by ransomware leak sites, with a total of 3,998 posts from various ransomware groups.
What drove this surge of activity? 2023 saw high-profile vulnerabilities like SQL injection for MOVEit and GoAnywhere MFT services. Zero-day exploits fo
Checkpoint
13th February – Threat Intelligence Report
blogs_checkpoint·2023-02-13·CVSS 9.8
CVE-2019-5544 [CRITICAL] 13th February – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 13th February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 13th February, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
The California cities of Oakland and Modesto have been targeted by ransomware attacks, disrupting services in the former and the police network in the latter. Also in California, healthcare company ‘Heritage Provider Network’ has confirmed that medical and personal information of more than 3 million patients had been disc
Tenable
Cybersecurity Snapshot: Check Out Our No-Holds-Barred Interview with ChatGPT
blogs_tenable·2023-02-10
Cybersecurity Snapshot: Check Out Our No-Holds-Barred Interview with ChatGPT
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Weltweite Ransomware-Welle nur der Anfang
blogs_trendmicro·2023-02-09
Weltweite Ransomware-Welle nur der Anfang
Ausnutzung von Schwachstellen
## Weltweite Ransomware-Welle nur der Anfang
Die weltweite Ransomware-Welle zeigt, dass Cyberkriminelle immer professioneller vorgehen. Die breite Streuung des Angriffs deutet aber auf das Motto „Masse statt Klasse“ hin. Auf eine zweite Welle sollten Unternehmen gut – mit XDR -- vorbereitet sein.
By: Richard Werner Feb 09, 2023 Read time: ( words)
Save to Folio
Derzeit hält wieder eine breitgestreute globale Ransomware-Welle die IT-Welt in Atem. Nach Aussagen des BSI ist auch eine mittlere dreistellige Zahl deutscher Systeme betroffen. Medienberichten zufolge zielen die Angreifer auf Server-Farmen (mit ESXi) und nutzen eine bereits im Februar 2021 gepatchte Schwachstelle aus. Server sind das Herzstück einer jeden IT-Landschaft, und das macht die betroffen
Qualys
Ransomware Targets Outdated VMware ESXi Hypervisors: Protect Your Systems Now! | Qualys
blogs_qualys·2023-02-08·CVSS 9.8
[CRITICAL] Ransomware Targets Outdated VMware ESXi Hypervisors: Protect Your Systems Now! | Qualys
#### Table of Contents
- Qualys QID Coverage
- Discover Vulnerable VMwares ESXi Using Qualys VMDR
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- ESXiArgs-Recover: A Solution for Ransomware Attacks on VMware ESXi Hypervisors
- Conclusion
- Contributors
Updated on February 8, 2023 at 2:40 PM Pacific Standard Time: This article has been updated with EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Updated on February 7, 2023 at 9:05 PM Pacific Standard Time: This article has been updated with the latest information on the ESXiArgs-Recovery Solution, a script offered by the Cybersecurity and Infrastructure Security Agency (CISA) for accessing encrypted virtual machines.
We wanted to bring to your attention a significant ransomware threat recently repor
Qualys
Ransomware Targets Outdated VMware ESXi Hypervisors: Protect Your Systems Now!
blogs_qualys·2023-02-08·CVSS 9.8
[CRITICAL] Ransomware Targets Outdated VMware ESXi Hypervisors: Protect Your Systems Now!
## Table of Contents
Qualys QID Coverage
Discover Vulnerable VMwares ESXi Using Qualys VMDR
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
ESXiArgs-Recover: A Solution for Ransomware Attacks on VMware ESXi Hypervisors
Conclusion
Contributors
Updated on February 8, 2023 at 2:40 PM Pacific Standard Time: This article has been updated with EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Updated on February 7, 2023 at 9:05 PM Pacific Standard Time: This article has been updated with the latest information on the ESXiArgs-Recovery Solution, a script offered by the Cybersecurity and Infrastructure Security Agency (CISA) for accessing encrypted virtual machines.
We wanted to bring to your attention a significant ransomware threat recently reported in th
Wiz
Ransomware attacks targeting VMware ESXi servers | Wiz Blog
blogs_wiz·2023-02-07·CVSS 8.8
CVE-2021-21974 [HIGH] Ransomware attacks targeting VMware ESXi servers | Wiz Blog
On February 3rd, 2023, researchers began observing attacks aimed at the VMware ESXi hypervisor with the goal of infecting them with ransomware. The affected systems are ESXi hypervisors version 6.5, 6.7 and 7.0.
These recent attacks, dubbed ESXiArgs, leverage CVE-2021-21974, a vulnerability which impacts the Service Location Protocol (SLP) service and grants an attacker the ability to execute arbitrary code remotely. A patch has been available for CVE-2021-21974 since February 23rd, 2021.
## What is CVE-2021-21974?
CVE-2021-21974 is a heap overflow vulnerability in OpenSLP, a network service that listens on TCP and UDP port 427 on default installations of VMware ESXi. A malicious actor that has access to port 427 could exploit the heap overflow issue in the OpenSLP service, leading to r
Wiz
Ransomware attacks targeting VMware ESXi servers | Wiz Blog
blogs_wiz·2023-02-07·CVSS 8.8
CVE-2021-21974 [HIGH] Ransomware attacks targeting VMware ESXi servers | Wiz Blog
On February 3rd, 2023, researchers began observing attacks aimed at the VMware ESXi hypervisor with the goal of infecting them with ransomware. The affected systems are ESXi hypervisors version 6.5, 6.7 and 7.0.
These recent attacks, dubbed ESXiArgs , leverage CVE-2021-21974, a vulnerability which impacts the Service Location Protocol (SLP) service and grants an attacker the ability to execute arbitrary code remotely. A patch has been available for CVE-2021-21974 since February 23rd, 2021.
## What is CVE-2021-21974?
CVE-2021-21974 is a heap overflow vulnerability in OpenSLP, a network service that listens on TCP and UDP port 427 on default installations of VMware ESXi. A malicious actor that has access to port 427 could exploit the heap overflow issue in the OpenSLP service, leading to
Checkpoint
6th February – Threat Intelligence Report
blogs_checkpoint·2023-02-06
CVE-2022-31711 6th February – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 6th February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 6th February, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHE
Check Point Research has flagged the Dingo crypto Token, with a market cap of $10,941,525 as a scam. The threat actors behind the token added a backdoor function in its smart contract, to manipulate the fee. Specifically, they used the “setTaxFeePercent” function within the token’s smart contract code to manipulate the buyin
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
# Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative
2022/07/27
Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service, VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c. In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/IP s
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
## Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative 2022/07/27 Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service , VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c . In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/IP
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
## Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative Jul 27, 2022 Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service , VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c . In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/
Tenable
CVE-2021-21985: Critical VMware vCenter Server Remote Code Execution
blogs_tenable·2021-05-25·CVSS 9.8
[CRITICAL] CVE-2021-21985: Critical VMware vCenter Server Remote Code Execution
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
CVE-2021-21972: VMware vCenter Server Remote Code Execution Vulnerability
blogs_tenable·2021-02-24·CVSS 9.8
[CRITICAL] CVE-2021-21972: VMware vCenter Server Remote Code Execution Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Recorded Future
ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers
blogs_recorded_future·CVSS 9.8
CVE-2021-21974 [CRITICAL] ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers
# ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers
An ongoing ransomware campaign dubbed ESXiArgs is targeting outdated VMware ESXi installations. While first reports surfaced on Friday, February 3rd, a more significant wave infected at least 2,000 hosts over the weekend, according to BleepingComputer. An internet-wide scan reported up to 8,000 infected hosts as of this writing.
The attack likely exploits CVE-2021-21974, a two-year-old remote code execution vulnerability in the bundled OpenSLP service, for which a patch has been available since February 2021.
VMware ESXi is a Type 1 hypervisor that runs directly on host server hardware, providing a virtualization layer capable of abstracting CPU, storage, memory, and networking resources into multiple virtual machines.
Crowdstrike
Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Threat Intel
Sea Turtle (Sea Turtle, Teal Kurma, Marbled Dust)
threat_intel
Sea Turtle (Sea Turtle, Teal Kurma, Marbled Dust)
# Threat Actor Profile: Sea Turtle
ATT&CK ID: G1041
Also known as: Sea Turtle, Teal Kurma, Marbled Dust, Cosmic Wolf, SILICON
## Overview
Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.(Citation: Talos Sea Turtle 2019)(Citation: Talos Sea Turtle 2019_2)(Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)
## Techniques (TTPs)
### Resource Development
- T1583 A
Greynoiseio
GreyNoise
blogs_greynoiseio·CVSS 8.8
[HIGH] GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Crowdstrike
Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Greynoiseio
Malicious Tag Roundup (May 24-Jun 4, 2021)
blogs_greynoiseio·CVSS 9.8
[CRITICAL] Malicious Tag Roundup (May 24-Jun 4, 2021)
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Recorded Future
ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers | Recorded Future
blogs_recorded_future·CVSS 9.8
CVE-2021-21974 [CRITICAL] ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers | Recorded Future
## ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers
An ongoing ransomware campaign dubbed ESXiArgs is targeting outdated VMware ESXi installations. While first reports surfaced on Friday, February 3rd, a more significant wave infected at least 2,000 hosts over the weekend, according to BleepingComputer . An internet-wide scan reported up to 8,000 infected hosts as of this writing.
The attack likely exploits CVE-2021-21974, a two-year-old remote code execution vulnerability in the bundled OpenSLP service, for which a patch has been available since February 2021.
VMware ESXi is a Type 1 hypervisor that runs directly on host server hardware, providing a virtualization layer capable of abstracting CPU, storage, memory, and networking resources into multiple virtual machines
Huntress
VMware ESXi Vulnerability: Analysis, Impact, Mitigation | Huntress
blogs_huntress·CVSS 8.8
CVE-2021-21974 [HIGH] VMware ESXi Vulnerability: Analysis, Impact, Mitigation | Huntress
## VMware ESXi Vulnerability
Written by: Monica Burgess
Published: 11/07/25
VMware ESXi vulnerabilities are security flaws in VMware's ESXi hypervisor, a critical component in virtualized environments. These vulnerabilities often involve remote code execution (RCE), denial of service (DoS), or privilege escalation , allowing attackers to compromise virtual machines. For example, CVE-2021-21974 is a heap overflow vulnerability that enables RCE, posing significant risks to organizations.
## When was it Discovered?
The VMware ESXi vulnerability CVE-2021-21974 was disclosed on February 23, 2021, by VMware. The vulnerability was publicly detailed shortly after, with proof-of-concept exploits emerging within weeks. VMware released patches promptly, but unpatched systems remain at risk.
##
http://packetstormsecurity.com/files/162957/VMware-ESXi-OpenSLP-Heap-Overflow.htmlhttps://www.vmware.com/security/advisories/VMSA-2021-0002.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-21-250/http://packetstormsecurity.com/files/162957/VMware-ESXi-OpenSLP-Heap-Overflow.htmlhttps://www.vmware.com/security/advisories/VMSA-2021-0002.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-21-250/
2021-02-24
Published
Exploited in the wild