Lucene search

K
nvd[email protected]NVD:CVE-2022-22960
HistoryApr 13, 2022 - 6:15 p.m.

CVE-2022-22960

2022-04-1318:15:13
CWE-732
web.nvd.nist.gov
4
vmware
privilege escalation
support scripts
local access

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

50.9%

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to โ€˜rootโ€™.

Affected configurations

Nvd
Node
vmwarecloud_foundationRange3.0โ€“5.0
OR
vmwareidentity_managerMatch3.3.3
OR
vmwareidentity_managerMatch3.3.4
OR
vmwareidentity_managerMatch3.3.5
OR
vmwareidentity_managerMatch3.3.6
OR
vmwarevrealize_automationRange8.0โ€“9.0
OR
vmwarevrealize_automationMatch7.6
OR
vmwarevrealize_suite_lifecycle_managerRange8.0โ€“9.0
OR
vmwareworkspace_one_accessMatch20.10.0.0
OR
vmwareworkspace_one_accessMatch20.10.0.1
OR
vmwareworkspace_one_accessMatch21.08.0.0
OR
vmwareworkspace_one_accessMatch21.08.0.1
AND
linuxlinux_kernelMatch-
VendorProductVersionCPE
vmwarecloud_foundation*cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
vmwareidentity_manager3.3.3cpe:2.3:a:vmware:identity_manager:3.3.3:*:*:*:*:*:*:*
vmwareidentity_manager3.3.4cpe:2.3:a:vmware:identity_manager:3.3.4:*:*:*:*:*:*:*
vmwareidentity_manager3.3.5cpe:2.3:a:vmware:identity_manager:3.3.5:*:*:*:*:*:*:*
vmwareidentity_manager3.3.6cpe:2.3:a:vmware:identity_manager:3.3.6:*:*:*:*:*:*:*
vmwarevrealize_automation*cpe:2.3:a:vmware:vrealize_automation:*:*:*:*:*:*:*:*
vmwarevrealize_automation7.6cpe:2.3:a:vmware:vrealize_automation:7.6:*:*:*:*:*:*:*
vmwarevrealize_suite_lifecycle_manager*cpe:2.3:a:vmware:vrealize_suite_lifecycle_manager:*:*:*:*:*:*:*:*
vmwareworkspace_one_access20.10.0.0cpe:2.3:a:vmware:workspace_one_access:20.10.0.0:*:*:*:*:*:*:*
vmwareworkspace_one_access20.10.0.1cpe:2.3:a:vmware:workspace_one_access:20.10.0.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

50.9%