First published: Fri May 20 2022(Updated: )
VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Identity Manager | =3.3.3 | |
VMware Identity Manager | =3.3.4 | |
VMware Identity Manager | =3.3.5 | |
VMware Identity Manager | =3.3.6 | |
VMware Workspace ONE Access | =20.10.0.0 | |
VMware Workspace ONE Access | =20.10.0.1 | |
VMware Workspace ONE Access | =21.08.0.0 | |
VMware Workspace ONE Access | =21.08.0.1 | |
Linux Linux kernel | ||
VMware Cloud Foundation | =4.0 | |
VMware Cloud Foundation | =4.0.1 | |
VMware Cloud Foundation | =4.1 | |
VMware Cloud Foundation | =4.1.0.1 | |
VMware Cloud Foundation | =4.2 | |
VMware Cloud Foundation | =4.2.1 | |
VMware Cloud Foundation | =4.3 | |
VMware Cloud Foundation | =4.3.1 | |
Vmware Vrealize Suite Lifecycle Manager | =8.0 | |
Vmware Vrealize Suite Lifecycle Manager | =8.0.1 | |
Vmware Vrealize Suite Lifecycle Manager | =8.1 | |
Vmware Vrealize Suite Lifecycle Manager | =8.2 | |
Vmware Vrealize Suite Lifecycle Manager | =8.2-patch1 | |
Vmware Vrealize Suite Lifecycle Manager | =8.2-patch2 | |
Vmware Vrealize Suite Lifecycle Manager | =8.2-patch3 | |
Vmware Vrealize Suite Lifecycle Manager | =8.3 | |
Vmware Vrealize Suite Lifecycle Manager | =8.3-patch1 | |
Vmware Vrealize Suite Lifecycle Manager | =8.3-patch2 | |
Vmware Vrealize Suite Lifecycle Manager | =8.3-patch3 | |
Vmware Vrealize Suite Lifecycle Manager | =8.4 | |
Vmware Vrealize Suite Lifecycle Manager | =8.4-patch1 | |
Vmware Vrealize Suite Lifecycle Manager | =8.4.1 | |
Vmware Vrealize Suite Lifecycle Manager | =8.4.1-patch1 | |
Vmware Vrealize Suite Lifecycle Manager | =8.4.1-patch2 | |
Vmware Vrealize Suite Lifecycle Manager | =8.4.1-patch3 | |
Vmware Vrealize Suite Lifecycle Manager | =8.6 | |
Vmware Vrealize Suite Lifecycle Manager | =8.6-patch1 | |
Vmware Vrealize Suite Lifecycle Manager | =8.6.1 | |
Vmware Vrealize Suite Lifecycle Manager | =8.6.2 | |
Vmware Vrealize Suite Lifecycle Manager | =8.7 | |
Vmware Vrealize Suite Lifecycle Manager | =8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22973
The severity of CVE-2022-22973 is high, with a CVSS score of 7.8.
VMware Workspace ONE Access and Identity Manager versions 3.3.3, 3.3.4, 3.3.5, and 3.3.6, as well as versions 20.10.0.0, 20.10.0.1, 21.08.0.0, and 21.08.0.1 are affected by CVE-2022-22973.
A malicious actor with local access can exploit this vulnerability to escalate privileges to 'root'.
More information about CVE-2022-22973 can be found in the VMware Security Advisory VMSA-2022-0014.