The proof-of-concept exploit code for the remote code execution (RCE) vulnerability (CVE-2021-21972) in VMware vCenter server has been publicly available on the Internet. Active scannings for Internet-accessible vulnerable vCenter servers have been observed. System administrators are advised to take immediate actions to patch your affected systems to mitigate the elevated risk of cyber attacks. It is advised not to expose VMware vCenter servers to the Internet if not necessary.
VMware vCenter Server (vCenter Server)
VMware Cloud Foundation (Cloud Foundation)
Depending on the vulnerabilities being exploited, a successful exploitation of the vulnerabilities could result in command execution with unrestricted privileges, remote code execution and information disclosure on the affected system.
Patches for affected products are available. System administrators of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.