CVE-2021-21974
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.
- Affected products
- Esxi
- Vmware Cloud Foundation
- < 3.10.1.2, 4.2
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 45.1% (99th percentile)
- Weakness
- CWE-787
- NVD status
- Modified
- Published
- 2021-02-24
CVE-2021-21974 at NVD
13 known exploits for CVE-2021-21974
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2021-21974
Feb2023-CVE-2021-21974-OSINT
CVE-2021-21974
cve-2021-21974
CVE-2021-21974
CVE-2021-21974_vuln_dectection
Exploit for Out-of-bounds Write in Vmware Cloud_Foundation
Exploit for Out-of-bounds Write in Vmware Cloud_Foundation
VMware ESXi OpenSLP Heap Overflow Exploit
VMware ESXi OpenSLP Heap Overflow
ESXi OpenSLP堆溢出漏洞(CVE-2021-21974)
Exploit for Out-of-bounds Write in Vmware Cloud_Foundation
Exploit for Out-of-bounds Write in Vmware Horizon_Daas