CVE-2022-22960
VMware Multiple Products: Privilege Escalation
As of , CVE-2022-22960 in VMware Multiple Products is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 15 April 2022
- US federal deadline
- 6 May 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.36Higher than 98% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- 0.01 on 15 April 2022EPSS on the day CISA listed it.
- Public exploit
- 1 Metasploit module
- Fix
- No vendor link in CISA's entry
What CISA says to do
Apply updates per vendor instructions.
CISA's required action
What the flaw is
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.
CISA's description
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.
The CVE record's description, from vmware
- CVE published
- 13 April 2022
- Assigned by
- vmware
- CVSS
- 7.8 High (CVSS 3.1, from CISA-ADP)
- CWE-732
- Incorrect Permission Assignment for Critical Resource
- CWE-250
- Execution with Unnecessary Privileges
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: VMware Workspace ONE Access CVE-2022-22960exploit module, rank good
Multiple Products: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2020-3950Privilege Escalation | VMware Multiple Products | Patch this weekMetasploit module; verified Exploit-DB entry | 0.07 | ||
| CVE-2020-4006Multiple VMware Products Command Injection | VMware Multiple Products | Patch soon | 0.17 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org