CVE-2017-4921: VMware vCenter Server

High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.

VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library that may lead to privilege escalation.

Affected products

  • VMware vCenter Server: version 6.5 only

Published 2017-08-01. Last modified 2026-06-17.