漏洞描述 2021年3月2日,VMware 官方发布安全公告,披露了CVE-2021-21978 VMware View Planner 远程代码执行漏洞。3月4日,漏洞利用代码在互联网上公开,攻击者构造恶意请求,可上传恶意文件,执行任意代码。
相关漏洞推荐 POC CVE-2018-6961: VMware NSX SD-WAN Edge - Command Injection (CVE-2025-41252) VMware NSX未认证的用户名枚举漏洞 (CVE-2025-41246) VMware Tools for Windows授权不当漏洞 (CVE-2025-41250)VMware vCenter SMTP头部注入漏洞 CVE-2023-20888: VMware Aria Operations for Networks - Remote Code Execution POC CVE-2021-21972: VMware vSphere Client (HTML5) - Remote Code Execution POC CVE-2021-21973: VMware vSphere - Server-Side Request Forgery POC CVE-2021-21978: VMware View Planner <4.6 SP1- Remote Code Execution POC CVE-2021-21985: VMware vSphere Client (HTML5) - Remote Code Execution POC CVE-2021-22005: VMware vCenter Server - Arbitrary File Upload POC CVE-2022-22954: VMware Workspace ONE Access - Server-Side Template Injection POC CVE-2022-22972: VMware Workspace ONE Access/Identity Manager/vRealize Automation - Authentication Bypass POC CVE-2022-31656: VMware - Local File Inclusion