Description
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
Remediation
Upgrade to the latest version of VMware vCenter.
References
Related Vulnerabilities
F5 iControl REST unauthenticated remote command execution vulnerability
Security update: Hotfix available for ColdFusion
WordPress Plugin Dynamic Content for Elementor Remote Code Execution (1.9.5.6)
Apache Log4j socket receiver deserialization vulnerability
Drupal 7 arbitrary PHP code execution and information disclosure