CVE-2022-22948

VMware vCenter Server: Incorrect Default File Permissions

As of , CVE-2022-22948 in VMware vCenter Server is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 17 July 2024
US federal deadline
7 August 202421 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.13Higher than 96% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.01 on 17 July 2024EPSS on the day CISA listed it.
Public exploit
1 Metasploit module
Fix
Vendor advice: www.vmware.comLinks below, from CISA's entry.

What CISA says to do

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA's required action

What the flaw is

VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information.

CISA's description

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.

The CVE record's description, from vmware

CVE published
29 March 2022
Assigned by
vmware
CVSS
6.5 Medium (CVSS 3.1, from CISA-ADP)
CWE-276
Incorrect Default Permissions
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

vCenter Server: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2020-3952Information DisclosureVMware vCenter ServerPatch this weekMetasploit module; EPSS 0.900.90
CVE-2021-21972Remote Code ExecutionVMware vCenter ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2021-21985Improper Input ValidationVMware vCenter ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2021-22005File UploadVMware vCenter ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2023-34048Out-of-Bounds WriteVMware vCenter ServerPatch this weekEPSS 0.990.99
CVE-2024-38812Heap-Based Buffer OverflowVMware vCenter ServerPatch this weekEPSS 0.550.55
CVE-2021-22017Improper Access ControlVMware vCenter ServerPatch soon0.49
CVE-2024-38813Privilege EscalationVMware vCenter ServerPatch soon0.17

Read further