CVE-2022-22960: VMware Multiple Products Privilege Escalation Vulnerability
Published Apr 13, 2022
·Updated
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.
Affected Software
26 affected components
VMware Multiple Products
VMware Cloud Foundation>=3.0<5.0
VMware Identity Manager=3.3.3
VMware Identity Manager=3.3.4
VMware Identity Manager=3.3.5
VMware Identity Manager=3.3.6
VMware vRealize Automation>=8.0<9.0
VMware vRealize Automation=7.6
VMware Vrealize Suite Lifecycle Manager>=8.0<9.0
VMware Workspace ONE Access=20.10.0.0
VMware Workspace ONE Access=20.10.0.1
VMware Workspace ONE Access=21.08.0.0
VMware Workspace ONE Access=21.08.0.1
Linux Linux kernel
All of the following
Any of the following
VMware Cloud Foundation>=3.0<5.0
VMware Identity Manager=3.3.3
VMware Identity Manager=3.3.4
VMware Identity Manager=3.3.5
VMware Identity Manager=3.3.6
VMware vRealize Automation=7.6
VMware Vrealize Suite Lifecycle Manager>=8.0<9.0
VMware Workspace ONE Access=20.10.0.0
VMware Workspace ONE Access=20.10.0.1
VMware Workspace ONE Access=21.08.0.0
VMware Workspace ONE Access=21.08.0.1
Linux Linux kernel
Remediation
Event History
Apr 13, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 15, 2022
Known Exploited
via CISA·12:00 AM
Frequently Asked Questions
1
What is CVE-2022-22960?
CVE-2022-22960 is a privilege escalation vulnerability in VMware Workspace ONE Access, Identity Manager, and vRealize Automation.
2
How severe is CVE-2022-22960?
CVE-2022-22960 has a severity rating of 7.8 (high).
3
Which software products are affected by CVE-2022-22960?
VMware Workspace ONE Access, Identity Manager, and vRealize Automation are affected by CVE-2022-22960.
4
How does CVE-2022-22960 work?
CVE-2022-22960 allows a malicious actor with local access to escalate privileges to 'root'.
5
Are there any patches available for CVE-2022-22960?
Patch information for CVE-2022-22960 can be found on the VMware website.