Friday, April 18, 2025
HomeCVE/vulnerabilityVMware vCenter Server Flaw Let Attacker Exploit to Perform Elevate Privileges Attack

VMware vCenter Server Flaw Let Attacker Exploit to Perform Elevate Privileges Attack

Published on

SIEM as a Service

Follow Us on Google News

There has finally been a patch released by VMware for an affected version of vCenter Server’s IWA mechanism, eight months after a high-severity privilege escalation vulnerability was disclosed.

CrowdStrike Security’s Yaron Zinar and Sagi Sheinfeld reported the vulnerability and it has been tracked as CVE-2021-22048 on their respective systems. 

It also affects the hybrid cloud platform VMware’s Cloud Foundation as well, along with the IWA mechanism built into the vCenter Server.

- Advertisement - Google News

An attacker can elevate privileges to a higher privileged group by successfully exploiting this vulnerability on unpatched vCenter Server deployments that do not require administrative access in order to execute malicious code.

Flaw profile

  • CVE ID: CVE-2021-22048
  • CVSS Score: 7.1
  • Advisory ID: VMSA-2021-0025.2
  • Summary: The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism.
  • Issue Date: 2021-11-10
  • Updated On: 2022-07-12

Products impacted

Here below we have mentioned all the products that are impacted by this security flaw:-

  • VMware vCenter Server (vCenter Server)
  • VMware Cloud Foundation (Cloud Foundation)

This bug has been rated critical by VMware, which means it is in the range of severity for a critical bug. It means that the data of a user is compromised in a completely unreliable way due to authorized attacks or user assistance, which leads to a complete compromise of data integrity or confidentiality.

Since there are multiple versions of vCenter Server that are affected by this vulnerability, that’s why VMware has released update 3f for vCenter Server 7.0.

Workaround

Since VMware’s security advisory was first published on November 10th, 2021, eight months ago, the company has provided a workaround to remove the attack vector.

VMware’s knowledgebase article claims that if an attack is attempted on Integrated Windows Authentication (IWA), administrators are advised to switch to Active Directory over LDAPs authentication or Identity Provider Federation for AD FS (vSphere 7.0 only) in order to prevent such attacks.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.

Latest articles

Ransomware Attacks Surge 126%, Targeting Consumer Goods and Services Sector

The cybersecurity landscape witnessed a dramatic escalation in ransomware attacks, marking a concerning trend...

CrazyHunter Hacker Group Exploits Open-Source GitHub Tools to Target Organizations

A relatively new ransomware outfit known as CrazyHunter has emerged as a significant threat,...

Threat Actors Leverage Cascading Shadows Attack Chain to Evade Detection and Hinder Analysis

A sophisticated multi-layered phishing campaign was uncovered, employing a complex attack chain known as...

Microsoft Vulnerabilities Reach Record High with Over 1,300 Reported in 2024

The 12th Edition of the Microsoft Vulnerabilities Report has revealed a significant surge in...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Ransomware Attacks Surge 126%, Targeting Consumer Goods and Services Sector

The cybersecurity landscape witnessed a dramatic escalation in ransomware attacks, marking a concerning trend...

CrazyHunter Hacker Group Exploits Open-Source GitHub Tools to Target Organizations

A relatively new ransomware outfit known as CrazyHunter has emerged as a significant threat,...

Threat Actors Leverage Cascading Shadows Attack Chain to Evade Detection and Hinder Analysis

A sophisticated multi-layered phishing campaign was uncovered, employing a complex attack chain known as...