HIGH
CVE-2022-22960
CVSS
7.8
KEV
Description
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.
Summary dbcve.org
VMware Workspace ONE Access, Identity Manager, and vRealize Automation contain a local privilege escalation vulnerability where improper file permissions on support scripts allow a locally authenticated attacker to execute those scripts with elevated root privileges.
Mitigation
Review and correct file permissions on support scripts in the affected installations—typically requires restricting execute permissions or changing ownership to root—and apply vendor-provided patches.
Weakness (CWE)
CWE-732
Incorrect Permission Assignment
EPSS Score
35.52%
Probability of exploitation in next 30 days
98.4th percentile
References
http://packetstormsecurity.com/files/171918/Mware-Workspace-ONE-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/171918/VMware-Workspace-ONE-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/171935/VMware-Workspace-ONE-Access-Privilege-Escalation.html
Exploit, Third Party Advisory, VDB Entry
https://www.vmware.com/security/advisories/VMSA-2022-0011.html
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22960
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.