CVE-2022-22948
published 2022-03-29CVE-2022-22948: The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to…
PriorityP277medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2024-08-07
Exploited in the wild
EPSS
13.94%
96.1th percentile
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | >= 3.0 < 3.11 | 3.11 |
| vmware | cloud_foundation | >= 4.0 < 4.4.1 | 4.4.1 |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →UNC3886 exploited CVE-2022-22948 to extract encrypted credentials from the vCenter PostgreSQL database (postgresDB); monitor for unauthorized read access to vCenter credential/config files with improper permissions
- →Post-exploitation tool 'vcenter_secrets_dump' (Metasploit module post/linux/gather/vcenter_secrets_dump.rb) targets vCenter appliance root shells to harvest dcAccountDN, dcAccountPassword, MACHINE_SSL, VMCA_ROOT, and SSO IdP certificates with private keys — monitor for execution of this module or equivalent file access patterns on vCenter appliances ↗
- →Monitor for harvesting and reuse of vCenter Server service accounts following exploitation of CVE-2022-22948, as UNC3886 leveraged these for lateral movement
- →CVE-2022-22948 is actively exploited in the wild (CISA KEV); prioritize detection of non-administrative access to sensitive vCenter files with incorrect default permissions ↗
- ·The Metasploit post-exploitation module only works against the vCenter Linux appliance, not Windows vCenter instances ↗
- ·CVE-2022-22948 requires non-administrative (but authenticated) access to vCenter Server to exploit; it is not an unauthenticated remote code execution vulnerability ↗
- ·UNC3886 has demonstrated the capability to replace indicators mentioned in open-source threat intelligence within under a week of publication, reducing the longevity of any specific IOCs associated with this CVE
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vulncheck6.5MEDIUM
cisa6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mgm9-ffv2-wpc6: The vCenter Server contains an information disclosure vulnerability due to improper permission of files
ghsa_unreviewed·2022-03-30
CVE-2022-22948 [MEDIUM] CWE-276 GHSA-mgm9-ffv2-wpc6: The vCenter Server contains an information disclosure vulnerability due to improper permission of files
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.
VulnCheck
VMware vCenter Server Incorrect Default File Permissions Vulnerability
vulncheck·2022·CVSS 6.5
CVE-2022-22948 [MEDIUM] CWE-276 VMware vCenter Server Incorrect Default File Permissions Vulnerability
VMware vCenter Server Incorrect Default File Permissions Vulnerability
VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information.
Affected: VMware vCenter Server
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://cloud.google.com/blog/topics/threat-intelligence/uncovering-unc3886-espionage-operations; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://blog.qualys.com/vulnerabilities-threat-research/2025/05/08/inside-lockbit-defense-lessons-from-the-leaked-lockbit-negotiations; https://www.trendmicro.com/en_no/research/25/g/revisiting-
CISA
VMware vCenter Server Incorrect Default File Permissions Vulnerability
cisa·2024-07-17·CVSS 6.5
CVE-2022-22948 [MEDIUM] CWE-276 VMware vCenter Server Incorrect Default File Permissions Vulnerability
Vulnerability: VMware vCenter Server Incorrect Default File Permissions Vulnerability
Affected: VMware vCenter Server
VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://www.vmware.com/security/advisories/VMSA-2022-0009.html; https://nvd.nist.gov/vuln/detail/CVE-2022-22948
Remediation Due Date: 2024-08-07
VMware
VMware vCenter Server updates address an information disclosure vulnerability (CVE-2022-22948)
vendor_vmware·2022-03-29·CVSS 6.5
CVE-2022-22948 [MEDIUM] VMware vCenter Server updates address an information disclosure vulnerability (CVE-2022-22948)
VMSA-2022-0009: VMware vCenter Server updates address an information disclosure vulnerability (CVE-2022-22948)
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.5.
CVEs: CVE-2022-22948
Affected products: VMware Cloud Foundation, VMware vCenter Server, vSphere
No detection rules found.
Trendmicro
Revisiting UNC3886 Tactics to Defend Against Present Risk
blogs_trendmicro·2025-07-28
Revisiting UNC3886 Tactics to Defend Against Present Risk
APT & Targeted Attacks
# Revisiting UNC3886 Tactics to Defend Against Present Risk
We examine the past tactics used by UNC3886 to gain insight on how to best strengthen defenses against the ongoing and emerging threats of this APT group.
By: Cj Arsley Mateo, Ieriz Nicolle Gonzalez, Jacob Santos, Paul John Bardon, Angelo Junio, Rayven Cervantes
2025/07/28
Read time: ( words)
Save to Folio
## Key Takeaways
- UNC3886 is an APT group that has historically targeted critical infrastructure, including telecommunications, government, technology, and defense, with a recent attack against Singapore.
- The group is known for rapidly exploiting zero-day and high-impact vulnerabilities in network and virtualization devices such as VMware vCenter/ESXi, Fortinet FortiOS, and Juniper Junos OS.
- UN
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
#### Table of Contents
- Who is LockBit? How it Evolved and Operates
- Monero: The Coin of the Realm
- Patch or Mitigate Now: Critical CVEs Exploited by LockBit
- Beyond Traditional Endpoints: Other Compromised Systems
- Initial Access and Deployment
- Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
## Table of Contents
Who is LockBit? How it Evolved and Operates
Monero: The Coin of the Realm
Patch or Mitigate Now: Critical CVEs Exploited by LockBit
Beyond Traditional Endpoints: Other Compromised Systems
Initial Access and Deployment
Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will leverage
Tenable
CVE-2022-22948: VMware vCenter Server Sensitive Information Disclosure Vulnerability
blogs_tenable·2022-03-30·CVSS 6.5
[MEDIUM] CVE-2022-22948: VMware vCenter Server Sensitive Information Disclosure Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Threat Intel
UNC3886 (UNC3886)
threat_intel
UNC3886 (UNC3886)
# Threat Actor Profile: UNC3886
ATT&CK ID: G1048
Also known as: UNC3886
Suspected origin: China
## Overview
UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.(Citation: Mandiant Fortinet Zero Day)(Citation: Google Cloud Threat Intelligence VMWare ESXi Zero-Day 2023)
## Campaigns
- **RedPenguin** (C0056) [2024-07-01T04:00:00.000Z to 2025-03-01T05:00:00.000Z]
The RedPenguin project was launched by Juniper in July 2024 to inv
2022-03-29
Published
2024-07-17
Added to CISA KEV
Exploited in the wild