CVE-2021-21999
Published on: 06/23/2021 12:00:00 AM UTC
Last Modified on: 07/12/2022 05:42:00 PM UTC
Certain versions of App Volumes from Vmware contain the following vulnerability:
VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerability. An attacker with normal access to a virtual machine may exploit this issue by placing a malicious file renamed as `openssl.cnf' in an unrestricted directory which would allow code to be executed with elevated privileges.
- CVE-2021-21999 has been assigned by
secu[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 7.2 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
ZDI-21-754 | Zero Day Initiative | www.zerodayinitiative.com text/html |
![]() |
VMSA-2021-0013 | www.vmware.com text/html |
![]() |
Related QID Numbers
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Vmware | App Volumes | All | All | All | All |
Application | Vmware | Remote Console | All | All | All | All |
Application | Vmware | Tools | All | All | All | All |
- cpe:2.3:a:vmware:app_volumes:*:*:*:*:*:*:*:*:
- cpe:2.3:a:vmware:remote_console:*:*:*:*:*:windows:*:*:
- cpe:2.3:a:vmware:tools:*:*:*:*:*:windows:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
VMSA-2021-0013 CVSSv3 Range:7.8 Issue Date:2021-06-22 CVE(s): CVE-2021-21999 Synopsis: VMware Tools, VMRC and VM… twitter.com/i/web/status/1… | 2021-06-22 22:17:27 |
![]() |
CVE-2021-21999 : VMware Tools for #Windows 11.x.y prior to 11.2.6 , VMware Remote Console for Windows 12.x prior… twitter.com/i/web/status/1… | 2021-06-23 12:06:12 |
![]() |
VMware Tools for Windows, VMware Remote Console (VMRC) for Windows and VMware App Volumes CVE-2021-21999 CVSS 7.8 p… twitter.com/i/web/status/1… | 2021-06-23 12:50:50 |
![]() |
CVE-2021-21999 VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to… twitter.com/i/web/status/1… | 2021-06-24 07:10:43 |
![]() |
As vulnerabilidades foram catalogadas como CVE-2021-21999 (CVSS 7.8) em todos os softwares e, segundo o fabricante,… twitter.com/i/web/status/1… | 2021-06-24 12:56:06 |
![]() |
■■■■□ CVE-2021-21999: VMware Workstation Tools Uncontrolled Search Path Element Local Privilege Escalation Vulnerab… twitter.com/i/web/status/1… | 2021-06-25 12:25:24 |
![]() |
CVE-2021-21999 | 2021-06-23 12:41:26 |