CVE-2021-21999 is a local privilege escalation vulnerability affecting VMware Tools for Windows, VMware Remote Console for Windows, and VMware App Volumes. An attacker with normal user access can exploit this by placing a specially named malicious file in an unrestricted directory, leading to code execution with elevated privileges. This high-severity vulnerability (CVSS 7.8) has a low attack complexity and can result in complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0, < 2.18.10CPE matchmatch criteria | cpe:2.3:a:vmware:app_volumes:*:*:*:*:*:*:*:* | ||
>= 4, < 2103CPE matchmatch criteria | cpe:2.3:a:vmware:app_volumes:*:*:*:*:*:*:*:* | ||
>= 12.0.0, < 12.0.1CPE matchmatch criteria | cpe:2.3:a:vmware:remote_console:*:*:*:*:*:windows:*:* | ||
>= 11.0.0, < 11.2.6CPE matchmatch criteria | cpe:2.3:a:vmware:tools:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.