Executive brief
VMware Workspace ONE Access, Identity Manager, and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A local attacker with low privileges can exploit this flaw to escalate their permissions to root.
Affected products
- VMware Workspace ONE Access 20.10.0.0, 20.10.0.1, 21.08.0.0, 21.08.0.1
- VMware Identity Manager 3.3.3, 3.3.4, 3.3.5, 3.3.6
- VMware vRealize Automation 7.6, 8.x
- VMware Cloud Foundation 3.0 to 5.0
- VMware vRealize Suite Lifecycle Manager 8.x
Timeline
- 2022-04-15: disclosed
- 2022-04-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-04-15: patched: VMware released VMSA-2022-0011 advisory and patches