HIGH

CVE-2022-22960

Vmware Cloud Foundation 2022-04-13 CVSS v3.1
CVSS
7.8
KEV

Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.

Summary dbcve.org

VMware Workspace ONE Access, Identity Manager, and vRealize Automation contain a local privilege escalation vulnerability where improper file permissions on support scripts allow a locally authenticated attacker to execute those scripts with elevated root privileges.

Mitigation

Review and correct file permissions on support scripts in the affected installations—typically requires restricting execute permissions or changing ownership to root—and apply vendor-provided patches.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-732 Incorrect Permission Assignment

EPSS Score

35.52%
Probability of exploitation in next 30 days
98.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE