High severity7.8NVD Advisory· Published Jun 23, 2021· Updated Jun 17, 2026
CVE-2021-21999
CVE-2021-21999
Description
VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerability. An attacker with normal access to a virtual machine may exploit this issue by placing a malicious file renamed as `openssl.cnf' in an unrestricted directory which would allow code to be executed with elevated privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:vmware:app_volumes:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:vmware:app_volumes:*:*:*:*:*:*:*:*range: >=2.0,<2.18.10
- (no CPE)range: 2.x < 2.18.10 and 4 < 2103
- VMware/Tools for Windowsdescription
- Range: <12.0.1
- Range: <11.2.6
Patches
Vulnerability mechanics
References
2- www.vmware.com/security/advisories/VMSA-2021-0013.htmlnvdPatchVendor Advisory
- www.zerodayinitiative.com/advisories/ZDI-21-754/nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.