---
title: "Critical Security Advisory for vCenter Servers: VMSA-2021-0010"
canonical: "https://www.virtcloudrocks.com/space/vblog01/blog/721083/Critical%20Security%20Advisory%20for%20vCenter%20Servers%3A%20VMSA-2021-0010"
format: markdown
---
VMware has released patches that address a new critical security advisory, [VMSA-2021-0010 (CVE-2021-21985 &  CVE-2021-21986).](https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.vmware.com%2Fsecurity%2Fadvisories%2FVMSA-2021-0010.html&data=04%7C01%7C%7C6dbdff76a1f64326f17b08d91fdce3c1%7C0edca4720b7146e696c70a68c10dcb96%7C0%7C0%7C637575855838778015%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=zbn5m14kMzvtNzFs2XW6sPH%2BGpzDQKJkmlbBmde%2FmZ4%3D&reserved=0) This needs your immediate attention. 

 

All the current supported vCenter Server versions – 6.5, 6.7 and 7.0 are impacted and hence all needs to be remediated.

 

The published VMSA on this outlines two issues that are resolved in the patch release – a remote code execution vulnerability in the vSAN plugin (regardless of whether you use vSAN or not) and improvements made to the vCenter Server plugin framework to better enforce plugin authentication.

 

The updates on vCenter Plugin authentication may cause some third-party plugins to stop working. VMware partners have been notified and are working to test their plugins (most continue to work), but there may be a period after updating when a virtualization admin team may need to access backup, storage, or other systems through their respective management interfaces and not through the vSphere Client UI. If a third-party plugin in your environment is affected, please contact the vendor that supplied it for an update.

 

As this impacts only vCenter Servers, it is easy to plan for update since it can be achieved by no down-time required for applications or VMs. This is a highly recommended update. 

 

Detailed information is available in the blog article : [<span style="color: #212529">**VMSA-2021-0010: What You Need to Know**</span>](https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fblogs.vmware.com%2Fvsphere%2F2021%2F05%2Fvmsa-2021-0010.html&data=04%7C01%7C%7C6dbdff76a1f64326f17b08d91fdce3c1%7C0edca4720b7146e696c70a68c10dcb96%7C0%7C0%7C637575855838788011%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=JtP%2FVpGbVkgGbHM3%2FXZKV3XAgnok%2F0s%2B5I4WtUmIb%2B4%3D&reserved=0)

 

**Quick Links:**

 

Remediation for vCenter Server 7.0 -  [Download Fix in vCenter Server 7.0 U2b](https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdocs.vmware.com%2Fen%2FVMware-vSphere%2F7.0%2Frn%2Fvsphere-vcenter-server-70u2b-release-notes.html&data=04%7C01%7C%7C6dbdff76a1f64326f17b08d91fdce3c1%7C0edca4720b7146e696c70a68c10dcb96%7C0%7C0%7C637575855838788011%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=x3hKvyghMmwHPVaDrY5JsYj%2FYXvAIm3FZ5Tc9MbbvvY%3D&reserved=0) OR [Workaround available in KB 83829](https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fkb.vmware.com%2Fs%2Farticle%2F83829&data=04%7C01%7C%7C6dbdff76a1f64326f17b08d91fdce3c1%7C0edca4720b7146e696c70a68c10dcb96%7C0%7C0%7C637575855838798002%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=Hhkxa44GGF%2FAUW4kgmZsanpn%2BUriDy0tNAnPtAOiNTI%3D&reserved=0)

Remediation for vCenter Server 6.7 – [Download Fix in vCenter Server 6.7 U3n](https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdocs.vmware.com%2Fen%2FVMware-vSphere%2F6.7%2Frn%2Fvsphere-vcenter-server-67u3n-release-notes.html&data=04%7C01%7C%7C6dbdff76a1f64326f17b08d91fdce3c1%7C0edca4720b7146e696c70a68c10dcb96%7C0%7C0%7C637575855838798002%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=xtaECYaoL9APbWwgHLsmehJE5CYcdgLPF7ZcV%2BMDY%2FI%3D&reserved=0) OR [Workaround available in KB 83829](https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fkb.vmware.com%2Fs%2Farticle%2F83829&data=04%7C01%7C%7C6dbdff76a1f64326f17b08d91fdce3c1%7C0edca4720b7146e696c70a68c10dcb96%7C0%7C0%7C637575855838798002%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=Hhkxa44GGF%2FAUW4kgmZsanpn%2BUriDy0tNAnPtAOiNTI%3D&reserved=0)

Remediation for vCenter Server 6.5 – [Download Fix in vCenter Server 6.5 U3p](https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdocs.vmware.com%2Fen%2FVMware-vSphere%2F6.5%2Frn%2Fvsphere-vcenter-server-65u3p-release-notes.html&data=04%7C01%7C%7C6dbdff76a1f64326f17b08d91fdce3c1%7C0edca4720b7146e696c70a68c10dcb96%7C0%7C0%7C637575855838808009%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=21n5OlqUjsMJkXpXz0cvb4YMVgLtIF2UWbAJTkp1RuE%3D&reserved=0) OR [Workaround available in KB 83829](https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fkb.vmware.com%2Fs%2Farticle%2F83829&data=04%7C01%7C%7C6dbdff76a1f64326f17b08d91fdce3c1%7C0edca4720b7146e696c70a68c10dcb96%7C0%7C0%7C637575855838808009%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=duAiN3fOp7k%2Bc8xz%2FUzwNd%2BXe0s7u%2FYst7FgKp1OM6g%3D&reserved=0)

 

[FAQ for VMSA 2021-0010](https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcore.vmware.com%2Fresource%2Fvmsa-2021-0010-faq&data=04%7C01%7C%7C6dbdff76a1f64326f17b08d91fdce3c1%7C0edca4720b7146e696c70a68c10dcb96%7C0%7C0%7C637575855838817990%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=XrfwcIcgxyIu6OXGMAbYedO4ZrgtMEiWXWJTUCUDWx4%3D&reserved=0)