Immunity, Inc.
Name vcenter_file_upload
CVE CVE-2021-22005
Exploit Pack CANVAS
Descriptionvcenter_file_upload
NotesCVE Name: CVE-2021-22005
VENDOR: VMWare
NOTES: This exploit upload a system crontab and execute commands to download the MOSDEF binary and execute it

VersionsAffected: VMWare vCenter 6.7 up to 7.0b
Repeatability: Infinite
References: https://www.vmware.com/security/advisories/VMSA-2021-0020.html
CVE Url: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22005
Date public: 9/14/2021
CVSS: 9.8

Learn more about the CANVAS Exploit Pack here: CANVAS