CVE-2021-22048
published 2021-11-10CVE-2021-22048: The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor…
PriorityP263high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
9.98%
95.1th percentile
The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | 3.0 – 3.10.2.2 | — |
| vmware | cloud_foundation | 4.0 – 4.1.0.1 | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability exists specifically in the IWA (Integrated Windows Authentication) authentication mechanism of vCenter Server; monitor for privilege escalation attempts by non-administrative users authenticating via IWA ↗
- →Affected products include VMware vCenter Server, VMware Cloud Foundation, and vSphere; audit group membership changes in vCenter for unexpected privilege escalations by non-admin accounts ↗
- ·The privilege escalation vulnerability is specific to the IWA (Integrated Windows Authentication) authentication mechanism; environments not using IWA may have reduced exposure ↗
- ·Exploitation requires at least non-administrative access to vCenter Server; fully unauthenticated exploitation is not indicated ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter Server updates address a privilege escalation vulnerability (CVE-2021-22048)
vendor_vmware·2021-11-10·CVSS 8.8
CVE-2021-22048 [HIGH] VMware vCenter Server updates address a privilege escalation vulnerability (CVE-2021-22048)
VMSA-2021-0025: VMware vCenter Server updates address a privilege escalation vulnerability (CVE-2021-22048)
The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.1.
CVEs: CVE-2021-22048
Affected products: VMware Cloud Foundation, VMware vCenter Server, vSphere
GHSA
GHSA-mcvx-m9qp-9vfp: The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism
ghsa_unreviewed·2022-05-24
CVE-2021-22048 [HIGH] CWE-269 GHSA-mcvx-m9qp-9vfp: The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism
The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/167733/VMware-Security-Advisory-2022-0025.2.htmlhttp://packetstormsecurity.com/files/167795/VMware-Security-Advisory-2021-0025.3.htmlhttps://www.vmware.com/security/advisories/VMSA-2021-0025.htmlhttp://packetstormsecurity.com/files/167733/VMware-Security-Advisory-2022-0025.2.htmlhttp://packetstormsecurity.com/files/167795/VMware-Security-Advisory-2021-0025.3.htmlhttps://www.vmware.com/security/advisories/VMSA-2021-0025.html
2021-11-10
Published