CVE-2021-39144βXStream Remote Code Execution Vulnerability
PUBLISHEDvulnerability record
2023-03-10 Β· last modified June 21, 2025
Metadata
Vulnerability Name
XStream Remote Code Execution Vulnerability
Description
XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation.
Known To Be Used in Ransomware Campaigns?
Action
Apply updates per vendor instructions.