A functional exploit for CVE-2021-22005, a vulnerability in VMware vCenter, has been released and is reportedly being used by malicious actors, according to experts tracking the issue.

See also: VMware: Critical bug in default vCenter Server installs
Last week, VMware warned of a critical vulnerability in its vCenter Server analytics service and urged users to update their systems as soon as possible.
On September 21, VMware said that vCenter Server is affected by an arbitrary file upload vulnerability in the Analytics, which would allow a malicious actor with network access to exploit this vulnerability to execute code on vCenter servers.
By September 24, VMware had confirmed reports that CVE-2021-22005 was being exploited by cybercriminals, and dozens of online security researchers reported mass scanning for vulnerable vCenter servers and publicly available exploit codes.
CISA issued its own warning on Friday, tweeting that they expected “widespread exploitation of VMware vCenter Server CVE-2021-22005.” Like VMware, they urged users to upgrade to a stable version as soon as possible or apply the temporary workaround provided by VMware.
See also: NSA, CISA: Guidelines for strengthening the security of VPN solutions
VMware reiterated that it has released patches and mitigations to address multiple vulnerabilities affecting VMware vCenter Server 6.5, 6.7, and 7.0. It has also issued public security advisories.

"Customer protection is VMware's top priority and we strongly recommend that affected customers immediately remediate as indicated in the advisory. As a best practice, VMware encourages all customers to apply the latest product updates, security patches, and mitigations available for their specific environments," the company said.
Derek Abdine, CTO of Censys, confirmed that they have reliably demonstrated that remote execution is possible and easy.
Will Dormann, a vulnerability analyst at CERT/CC, also confirmed on Twitter that the exploit for CVE-2021-22005 is now fully public.
Abdine noted that while a patch has been available for days, there is a “patch saturation” phenomenon where the patch never reaches 100%.
Now that an exploit has been released, Abdine added that the "gates have opened," allowing any attacker with lower technical skills to execute a mass exploit.
See also: VMware: Serious vulnerabilities in vCenter - Update immediately!
John Bambenek, a threat researcher at Netenrich, said that remote code execution as root on these types of devices is quite significant.
Almost every organization runs virtual machines, and if a threat actor has root access, they could infect every machine in that environment or steal the data on those virtual machines with relative ease.
