cbcvebase.
CVE-2021-21974
published 2021-02-24

CVE-2021-21974: OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A…

PriorityP189high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVRansomwareInitial access
Exploited in the wild
EPSS
45.06%
98.6th percentile
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.

Affected

5 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation>= 3.0 < 3.10.1.23.10.1.2
vmwarecloud_foundation>= 4.0 < 4.24.2
vmwareesxi
vmwareesxi
vmwareesxi

Detection & IOCsextracted from sources · hover to see the quote

ip80.82.77.139
ip80.82.77.33
ip185.165.190.17
ip71.6.199.23
ip93.174.95.106
ip185.165.190.34
ip193.37.255.114
ip71.6.135.131
ip89.248.167.131
ip185.142.236.35
ip185.142.236.34
ip185.142.236.36
ip195.144.21.56
ip152.89.196.211
ip104.152.52.55
ip193.163.125.138
ip43.130.10.173
ip104.152.52.0/24
port427
path/tmp/public.pem
filenameencrypt
filenameencrypt.sh
path/tmp/encrypt
filenameargsfile
  • Monitor for presence of ESXiArgs ransomware dropper files in /tmp: 'encrypt', 'encrypt.sh', and 'public.pem' — their presence is a confirmed post-exploitation IOC.
  • Alert on inbound TCP/UDP connections to port 427 (OpenSLP) from untrusted or external sources on ESXi hosts, as this is the attack entry point for CVE-2021-21974.
  • Detect ransomware activity by monitoring for mass termination of VMX processes (VM shutdown attempts) followed by encryption of .vmdk, .vmx, .vmxf, .vmsd, .vmsn, .vswp, .vmss, .nvram, and .vmem files.
  • Check Point IPS signature available for detection: 'VMWare OpenSLP Heap Buffer Overflow (CVE-2019-5544; CVE-2021-21974)'.
  • Detect creation of 'argsfile' on ESXi hosts, used by the malware to store encryption parameters (MB to skip, MB per encryption block, file size).
  • CERT-FR notes that encrypted .vmdk files may be renamed with a .args extension — monitor for this file extension change as a ransomware indicator.
  • ·CVE-2021-21974 is not yet officially confirmed as the sole attack vector; CVE-2020-3992 (also an OpenSLP vulnerability) has been listed by French CERT as another possibility.
  • ·The OpenSLP service (port 427) is disabled by default on new ESXi installations since ESXi 7.0 U2c and ESXi 8.0 GA — exploitation requires the service to be running and port 427 reachable.
  • ·The VM shutdown step (killing VMX process) used by the ransomware to unlock files before encryption is not reliably successful, which may leave files locked and unencrypted — reducing actual encryption impact in some cases.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:P
vulncheck8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.