⚠ Actively exploited
Added to CISA KEV on 2022-04-15. Federal agencies required to patch by 2022-05-06. Required action: Apply updates per vendor instructions..

CVE-2022-22960Incorrect Permission Assignment in Vmware Cloud Foundation

Severity
7.8HIGHNVD
EPSS
70.4%
top 1.31%
CISA KEV
KEV
Added 2022-04-15
Due 2022-05-06
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedApr 13
KEV addedApr 15
KEV dueMay 6
Latest updateMay 20
CISA Required Action: Apply updates per vendor instructions.

Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-8r7c-vjv4-wp6x: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in supp2022-04-14
CVEList
CVE-2022-22960: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in supp2022-04-13
VulnCheck
VMware Multiple Products Privilege Escalation Vulnerability2022

💥Exploits & PoCs

1
Metasploit
VMware Workspace ONE Access CVE-2022-22960

📋Vendor Advisories

2
CISA
VMware Multiple Products Privilege Escalation Vulnerability2022-04-15
VMware
VMware Workspace ONE Access, Identity Manager and vRealize Automation updates address multiple vulnerabilities.2022-04-06

🕵️Threat Intelligence

1
Unit42
Threat Brief: VMware Vulnerabilities Exploited in the Wild (CVE-2022-22954 and Others)2022-05-20
CVE-2022-22960 — Incorrect Permission Assignment | cvebase