CVE-2022-31661: High severity vmware workspace one access and identity manager vulnerability
Published Aug 5, 2022
·Updated
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can escalate privileges to 'root'.
Affected Software
14 affected components
VMware Identity Manager=3.3.4
VMware Identity Manager=3.3.5
VMware Identity Manager=3.3.6
VMware ONE Access=21.08.0.0
VMware ONE Access=21.08.0.1
Linux Linux kernel
VMware Access Connector=21.08.0.0
VMware Access Connector=21.08.0.1
VMware Access Connector=22.05
VMware Identity Manager Connector=3.3.4
VMware Identity Manager Connector=3.3.5
VMware Identity Manager Connector=3.3.6
VMware Identity Manager Connector=19.03.0.1
Microsoft Windows
Remediation
Event History
Aug 5, 2022
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-31661?
CVE-2022-31661 is a privilege escalation vulnerability in VMware Workspace ONE Access, Identity Manager, and vRealize Automation.
2
How severe is CVE-2022-31661?
CVE-2022-31661 has a severity score of 7.8, which is considered high.
3
Which software versions are affected by CVE-2022-31661?
VMware Workspace ONE Access (versions 3.3.4, 3.3.5, and 3.3.6) and VMware One Access (versions 21.08.0.0 and 21.08.0.1) are affected by CVE-2022-31661.
4
How can a malicious actor exploit CVE-2022-31661?
A malicious actor with local access can exploit CVE-2022-31661 to escalate privileges to 'root'.
5
Where can I find more information about CVE-2022-31661?
You can find more information about CVE-2022-31661 in the VMware Security Advisory VMSA-2022-0021.