Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security, Veeam & DevOps

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
  1. Home
  2. Breadcrumb-Yoast

[wpseo_breadcrumb]

CVE-2021-22048: VMware vCenter Server updates address a privilege escalation vulnerability

Posted on 12/10/202212/10/2023 IT Expert By IT Expert No Comments on CVE-2021-22048: VMware vCenter Server updates address a privilege escalation vulnerability
  1. Home
  2. Security | Vulnerability Scans and Assessment
  3. CVE-2021-22048: VMware vCenter Server updates address a privilege escalation vulnerability
vcenter_sign_on

VMware vCenter Server is advanced server management software that provides a centralized platform for controlling your VMware vSphere environments. It allows you to automate and deliver a virtual infrastructure across the hybrid cloud with confidence. With VMware Center, you gain centralized visibility, simplified and efficient management at scale, and extensibility across the hybrid cloud from a single console. Here are some related articles: Boot failure: How to fix EFI network timeout on VMware Workstation,. And how to solve VMware workstation .lck error. This article will show you how to resolve CVE-2021-22048: VMware vCenter Server updates address a privilege escalation vulnerability.

The following vulnerability was reported by Yaron Zinar and Sagi Sheinfeld of Crowdstrike to Vmware. The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism.

VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.1. Please see Differences between vSphere and ESXi and vCenter.

Impacted Products

The following solutions below are affected.

  • VMware vCenter Server (vCenter Server)
  • VMware Cloud Foundation (Cloud Foundation)

Please here are some exciting articles: VMware vCenter Server and Cloud Foundation: Workaround for CVE2021-22048, vCenter Server File Upload Vulnerability [CRITICAL], vCenter Converter removed from available downloads on VMware use Veeam, how to enable Exploit Protection on Windows using Windows, and CVE-2022-22948. Patch available to address vCenter Server information disclosure vulnerability.

What Exploit Does this Vulnerability Present?

A malicious actor with non-administrative access to the vCenter Server may exploit this issue to elevate privileges to a higher privileged group.

Workarounds to resolve CVE-2021-22048: VMware vCenter Server updates address a privilege escalation vulnerability

There are currently no updates (patches) to mitigate this vulnerability. But here is the workaround for CVE-2021-22048: switch to AD over LDAPS authentication.

OR Identity Provider Federation for AD FS (vSphere 7.0 or later) from Integrated Windows Authentication (IWA) as documented in the KB listed in the ‘Workarounds’ column of the ‘Response Matrix’ below.

ProductVersionRunning OnCVE IdentifierCVSSv3SeverityFixed VersionWorkaroundsAdditional Documentation
vCenter Server8.0AnyCVE-2021-220487.1Important Patch PendingKB86292None
vCenter Server7.0AnyCVE-2021-220487.1Important Patch Pending [1]KB86292KB89027 [1]
vCenter Server6.7AnyCVE-2021-220487.1Important Patch PendingKB86292None
vCenter Server6.5AnyCVE-2021-220487.1Important Patch PendingKB86292None

Impacted Product Suites that Deploy Response Matrix Components:

ProductVersionRunning OnCVE IdentifierCVSSv3SeverityFixed VersionWorkaroundsAdditional Documentation
Cloud Foundation (vCenter Server)4.xAnyCVE-2021-220487.1Important Patch pendingKB86292None
Cloud Foundation (vCenter Server)3.xAnyCVE-2021-220487.1Important Patch PendingKB86292None

Note: VMware has determined that vCenter 7.0u3f updates previously mentioned in the response matrix do not remediate CVE-2021-22048. It may introduce a functional issue for customers using IWA. Please review KB89027 for more information.

I hope you found this short piece on “CVE-2021-22048: VMware vCenter Server updates address a privilege escalation vulnerability” useful. If you have any questions, please let me know in the comment session.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Security | Vulnerability Scans and Assessment, Virtualization Tags:VMware, vulnerability

Post navigation

Previous Post: VMSA-2022-0026: An arbitrary file read vulnerability in VMware Aria Operations
Next Post: How to install Oracle VirtualBox on a Mac device

Related Posts

  • Burn ISO on MAC   Proxmox installation
    Create a bootable USB on Mac: Proxmox VE Setup Virtualization
  • apply and install Veeam NFR Licence
    How to apply and install Veeam NFR License Backup
  • Windows BootProcess
    Measured Boot, Secure Boot, Trusted Boot, and Early Launch Anti-Malware: How to secure the Windows 10 boot process Security | Vulnerability Scans and Assessment
  • HiveNightmare
    Workaround for “SeriousSAM or HiveNightmare” registry vulnerability for Windows 10 and 11 Security | Vulnerability Scans and Assessment
  • Free up filesystem root space
    How to fix the Filesystem root is running low on Disk space Virtualization
  • VMware Aria
    VMSA-2022-0026: An arbitrary file read vulnerability in VMware Aria Operations Security | Vulnerability Scans and Assessment

More Related Articles

Burn ISO on MAC   Proxmox installation Create a bootable USB on Mac: Proxmox VE Setup Virtualization
apply and install Veeam NFR Licence How to apply and install Veeam NFR License Backup
Windows BootProcess Measured Boot, Secure Boot, Trusted Boot, and Early Launch Anti-Malware: How to secure the Windows 10 boot process Security | Vulnerability Scans and Assessment
HiveNightmare Workaround for “SeriousSAM or HiveNightmare” registry vulnerability for Windows 10 and 11 Security | Vulnerability Scans and Assessment
Free up filesystem root space How to fix the Filesystem root is running low on Disk space Virtualization
VMware Aria VMSA-2022-0026: An arbitrary file read vulnerability in VMware Aria Operations Security | Vulnerability Scans and Assessment

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • GitLabrunner 1 1
    There has been a runner system failure: failed to start the process exec “pwsh” Containers
  • posfix as an smtp server
    How to Install and Configure Postfix as a Send-Only SMTP Server Linux
  • Windows Server 2016 1 1
    Merits and demerits of Local System Account and Service Logon Account Windows Server
  • Screenshot 2021 02 05 at 22.40.51
    Disable automatic screen lock on Ubuntu Desktop Linux
  • Featured image Microsoft Whiteboard
    How to work with Microsoft Blackboard via private or commercial accounts Microsoft Exchange/Office/365
  • Enable Hyper V on Windows 11 Create a VM with PowerShell
    Run Hyper-V on Windows 11: Convert Physical PC to Hyper-V VM Virtualization
  • EC2 Public IP
    How to Allocate, Associate, Disassociate and Release Elastic IP Address from an EC2 Instance AWS/Azure/OpenShift
  • How to create a dev drive
    How to create a Dev Drive on Windows 11 Windows

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,803 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.