
CVE-2021-22005 Explained: VMware vCenter Unauthenticated RCE
CVE-2021-22005 is a critical unauthenticated file upload vulnerability in VMware vCenter Server's CEIP analytics service. Disclosed September 2021, it allowed any attacker with network access to the vCenter HTTPS interface to upload an arbitrary file and achieve remote code execution as the vCenter service account, effectively granting control of every managed virtual machine. Mass exploitation began within 48 hours of disclosure.
