CVE-2022-22951
published 2022-03-23CVE-2022-22951: VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection…
PriorityP269critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
EPSS
21.93%
97.4th percentile
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute commands on the server due to improper input validation leading to remote code execution.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | carbon_black_app_control | >= 8.5 < 8.5.14 | 8.5.14 |
| vmware | carbon_black_app_control | >= 8.6 < 8.6.6 | 8.6.6 |
| vmware | carbon_black_app_control | >= 8.7.0 < 8.7.4 | 8.7.4 |
| vmware | carbon_black_app_control | >= 8.8.0 < 8.8.2 | 8.8.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-22951 is an OS command injection vulnerability in VMware Carbon Black App Control; exploitation requires an authenticated, high-privileged actor with network access to the administration interface — monitor for unexpected OS-level command execution originating from the App Control admin interface process ↗
- →Focus detection on the VMware Carbon Black App Control administration interface as the attack vector; anomalous or unexpected child processes spawned from the App Control server process may indicate exploitation ↗
- ·Vulnerability affects specific version ranges only: 8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4, and 8.8.x prior to 8.8.2 — detections should be scoped to unpatched instances within these ranges ↗
- ·Exploitation requires authentication with high privileges; detections targeting unauthenticated or low-privilege sessions will not apply to this CVE ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hgxf-8v8v-6qg4: VMware Carbon Black App Control (8
ghsa_unreviewed·2022-03-24
CVE-2022-22951 [CRITICAL] CWE-78 GHSA-hgxf-8v8v-6qg4: VMware Carbon Black App Control (8
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute commands on the server due to improper input validation leading to remote code execution.
VMware
VMware Carbon Black App Control update addresses multiple vulnerabilities (CVE-2022-22951, CVE-2022-22952)
vendor_vmware·2022-03-23·CVSS 9.1
CVE-2022-22951 [CRITICAL] VMware Carbon Black App Control update addresses multiple vulnerabilities (CVE-2022-22951, CVE-2022-22952)
VMSA-2022-0008: VMware Carbon Black App Control update addresses multiple vulnerabilities (CVE-2022-22951, CVE-2022-22952)
VMware Carbon Black App Control contains an OS command injection vulnerability. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.1.
CVEs: CVE-2022-22951, CVE-2022-22952
Affected products: VMware Carbon Black
No detection rules found.
No public exploits indexed.
2022-03-23
Published