The GreyNoise Blog

Get the latest tips and stories on improving information security.
Subscribe to our RSS Feed

Exploit Vector Analysis of Emerging ‘ESXiArgs’ Ransomware

In recent days CVE-2021-21974, a heap-overflow vulnerability in VMWare ESXi’s OpenSLP service has been prominently mentioned in the news in relation to a wave of ransomware effecting numerous organizations. The relationship between CVE-2021-21974 and the ransomware campaign may be blown out of proportion. We do not currently know what the initial access vector is, and it is possible it could be any of the vulnerabilities related to ESXi’s OpenSLP service. The objective of the following document is to provide clarity to network defenders surrounding the ransomware campaign.