CVE-2022-31664: High severity vmware workspace one access and identity manager vulnerability
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-31664?
CVE-2022-31664 is a vulnerability that exists in VMware Workspace ONE Access, Identity Manager, and vRealize Automation, allowing a local attacker to escalate privileges to 'root'.
Which software are affected by CVE-2022-31664?
VMware Identity Manager versions 3.3.4, 3.3.5, and 3.3.6, VMware ONE Access versions 21.08.0.0 and 21.08.0.1, and VMware Access Connector versions 21.08.0.0, 21.08.0.1, and 22.05 are affected by CVE-2022-31664.
What is the severity of CVE-2022-31664?
CVE-2022-31664 has a severity rating of 7.8 (high).
How can the privilege escalation vulnerability in CVE-2022-31664 be fixed?
Update to the patched versions of the affected software: VMware Identity Manager 3.3.7, VMware ONE Access 21.08.0.2, and VMware Access Connector 22.05.1.
Where can I find more information about CVE-2022-31664?
You can find more information about CVE-2022-31664 in the VMware Security Advisory VMSA-2022-0021.