CVE-2022-22962: High severity vmware horizon vulnerability
VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22962?
CVE-2022-22962 is a vulnerability in VMware Horizon Agent for Linux that allows a local privilege escalation by changing the default shared folder location.
What is the severity of CVE-2022-22962?
CVE-2022-22962 has a severity score of 7.8, which is considered high.
How does CVE-2022-22962 work?
CVE-2022-22962 exploits a vulnerable symbolic link in VMware Horizon Agent for Linux, allowing a user to link to a root owned file and gain escalated privileges.
What is the affected software?
The affected software is VMware Horizon Agent for Linux prior to version 22.x.
How can CVE-2022-22962 be mitigated?
To mitigate CVE-2022-22962, users should update to version 22.x or higher of VMware Horizon Agent for Linux.