High severity7.8NVD Advisory· Published Sep 23, 2021· Updated Jun 17, 2026
CVE-2021-22015
CVE-2021-22015
Description
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their privileges to root on vCenter Server Appliance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:vmware:vcenter_server:6.5:-:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:vmware:vcenter_server:6.5:-:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:7.0:-:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
2- www.vmware.com/security/advisories/VMSA-2021-0020.htmlnvdPatchVendor Advisory
- packetstormsecurity.com/files/170116/VMware-vCenter-vScalation-Privilege-Escalation.htmlnvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.