Junglewise Threat Intelligence

CVE-2022-22960: VMware Multiple Products Privilege Escalation Vulnerability

CVE-2022-22960 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-04-15

Technologies: VMware Cloud Foundation, VMware Workspace ONE Access, Apple Multiple Products, VMware Identity Manager. Vendors: VMware, Apple.

Executive brief

VMware Workspace ONE Access, Identity Manager, and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A local attacker with low privileges can exploit this flaw to escalate their permissions to root.

Affected products

  • VMware Workspace ONE Access 20.10.0.0, 20.10.0.1, 21.08.0.0, 21.08.0.1
  • VMware Identity Manager 3.3.3, 3.3.4, 3.3.5, 3.3.6
  • VMware vRealize Automation 7.6, 8.x
  • VMware Cloud Foundation 3.0 to 5.0
  • VMware vRealize Suite Lifecycle Manager 8.x

Timeline

  • 2022-04-15: disclosed
  • 2022-04-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-15: patched: VMware released VMSA-2022-0011 advisory and patches

Related threats