First published: Wed Feb 21 2024(Updated: )
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Aria Operations | ||
VMware Aria Operations | >=8.6.0<8.16.0 | |
VMware Cloud Foundation | >=4.0<=5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-22235 is high due to its local privilege escalation capabilities.
To fix CVE-2024-22235, apply the latest patches and updates provided by VMware for Aria Operations.
CVE-2024-22235 affects users of VMware Aria Operations and VMware Cloud Foundation versions within the specified ranges.
CVE-2024-22235 requires local administrative access, meaning it cannot be exploited remotely.
If you suspect a compromise due to CVE-2024-22235, immediately revoke access and conduct a thorough security assessment.