cbcvebase.
CVE-2021-22048
published 2021-11-10

CVE-2021-22048: The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group.

Affected

5 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation3.0 – 3.10.2.2
vmwarecloud_foundation4.0 – 4.1.0.1
vmwarevcenter_server
vmwarevcenter_server
vmwarevcenter_server