Database/Kernel, userspace & hypervisor
VMware ESXi (OpenSLP): OpenSLP heap overflow - the ESXiArgs ransomware entry point that mass-encrypted thousands
CVE-2021-21974Kernel, userspace & hypervisorKnown exploitedcurated
Impact
OpenSLP heap overflow - the ESXiArgs ransomware entry point that mass-encrypted thousands of hosts [KEV]
Who can reach it
Unauthenticated network on the same segment
What to do
Patch + disable SLP. The canonical example of why the hypervisor management plane must never share a broadcast domain with tenants
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.