cbcvebase.
CVE-2022-22951
published 2022-03-23

CVE-2022-22951: VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection…

PriorityP269critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
EPSS
21.93%
97.4th percentile
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute commands on the server due to improper input validation leading to remote code execution.

Affected

4 ranges
VendorProductVersion rangeFixed in
vmwarecarbon_black_app_control>= 8.5 < 8.5.148.5.14
vmwarecarbon_black_app_control>= 8.6 < 8.6.68.6.6
vmwarecarbon_black_app_control>= 8.7.0 < 8.7.48.7.4
vmwarecarbon_black_app_control>= 8.8.0 < 8.8.28.8.2

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2022-22951 is an OS command injection vulnerability in VMware Carbon Black App Control; exploitation requires an authenticated, high-privileged actor with network access to the administration interface — monitor for unexpected OS-level command execution originating from the App Control admin interface process
  • Focus detection on the VMware Carbon Black App Control administration interface as the attack vector; anomalous or unexpected child processes spawned from the App Control server process may indicate exploitation
  • ·Vulnerability affects specific version ranges only: 8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4, and 8.8.x prior to 8.8.2 — detections should be scoped to unpatched instances within these ranges
  • ·Exploitation requires authentication with high privileges; detections targeting unauthenticated or low-privilege sessions will not apply to this CVE

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.