Ransomware groups have begun actively exploiting critical, unauthenticated vulnerabilities in VMware vCenter Server, a significant escalation that moves the threat from espionage to direct operational and financial risk for organizations globally. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent advisory confirming this development, highlighting the severe danger to enterprises and government entities using VMware's widely-deployed virtualization management platform.

The exploitation centers on two flaws, CVE-2021-22005 and CVE-2021-21985, both with critical CVSS scores. They allow an attacker with network access to a vCenter management interface to execute arbitrary code without any credentials. Although VMware issued patches in July, security researchers report tens of thousands of internet-facing vCenter servers remain unprotected and vulnerable to scanning and compromise.

The shift to ransomware operations fundamentally changes the risk profile. Researchers note that a compromised vCenter server acts as a "skeleton key," granting attackers control over the entire virtualized environment from a single console. This allows for rapid lateral movement and the simultaneous encryption of virtual machines across a data center, maximizing the attack's impact.

For system administrators, the CISA alert signals an urgent patching priority. Delayed remediation leaves core infrastructure exposed to a high-impact attack vector. VMware has provided a workaround script for environments where patching cannot be immediate, but security teams must evaluate the functional trade-offs of this interim step against the unprotected risk.

The situation underscores a persistent systemic challenge: the gap between patch release and widespread exploitation remains alarmingly short. The prevalence of vulnerable servers months after fixes were available points to ongoing difficulties in maintaining robust patch cycles for critical infrastructure software. As a fundamental defensive layer, implementing strict network segmentation and stringent access controls for vCenter interfaces is essential to reduce the attack surface.

Given the opportunistic and financially motivated nature of these ransomware campaigns, VMware administrators must treat this advisory as a critical call to action. The combination of easy-to-exploit vulnerabilities and the devastating potential for business disruption makes securing vCenter installations a top-tier operational concern.


勒索軟件組織已開始積極利用VMware vCenter伺服器中兩個未經身份驗證的嚴重漏洞。此重大升級將威脅性質從間諜活動提升至對全球各機構構成直接的營運及財務風險。美國網絡安全及基礎設施安全局(CISA)發布緊急通告確認此發展,並強調使用VMware廣泛部署虛擬化管理平台的企業及政府機構面臨嚴重危險。

漏洞利用集中於CVE-2021-22005及CVE-2021-21985兩個評分為嚴重(CVSS)的缺陷。攻擊者只需網絡訪問vCenter管理介面,便能在無需任何憑證的情況下執行任意代碼。儘管VMware已於七月發布修補程式,但安全研究人員報告指出,仍有數萬台面向互聯網的vCenter伺服器未受保護,易遭掃描及入侵。

向勒索軟件操作的轉變從根本上改變了風險狀況。研究人員指出,被入侵的vCenter伺服器如同「萬能鑰匙」,使攻擊者能透過單一控制台接管整個虛擬化環境。這使得攻擊者能快速進行橫向移動,並同時加密數據中心內的虛擬機,從而將攻擊影響最大化。

對系統管理員而言,CISA警報意味著修補程式應列為緊急首要任務。延遲補救將使核心基礎設施暴露於高影響攻擊向量之下。VMware已為無法立即安裝修補程式的環境提供變通腳本,但安全團隊必須評估此過渡措施的功能取捨,對比未受保護的風險。

此情況凸顯了一項持續存在的系統性挑戰:從修補程式發布到大規模利用之間的時間差短得驚人。修補措施已發布數月後仍有大量易受攻擊伺服器存在,顯示維護關鍵基礎設施軟件的穩健修補週期面臨持續困難。作為基本防禦層,實施嚴格的網絡分段及針對vCenter介面的嚴謹存取控制,對於縮減攻擊面至關重要。

鑑於這些勒索軟件攻擊活動的投機性及財務動機本質,VMware管理員必須將此通告視為關鍵行動號召。易被利用的漏洞與可能造成業務中斷的毀滅性潛力相結合,使得確保vCenter安裝安全成為最優先的營運關注事項。

新聞來源 / Original News Source