CVE-2022-22952

Severity
9.1CRITICAL
EPSS
0.8%
top 26.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 23
Latest updateMar 24

Description

VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface may be able to execute code on the Windows instance where AppC Server is installed by uploading a specially crafted file.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 2.3 | Impact: 6.0

Affected Packages2 packages

NVDvmware/carbon_black_app_control8.58.5.14+3
CVEListV5vmware_carbon_black_app_control_(appc)VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qvxw-xhgh-w34w: VMware Carbon Black App Control (82022-03-24
CVEList
CVE-2022-22952: VMware Carbon Black App Control (82022-03-23

📋Vendor Advisories

1
VMware
VMware Carbon Black App Control update addresses multiple vulnerabilities (CVE-2022-22951, CVE-2022-22952)2022-03-23