cbcvebase.
CVE-2022-22960
published 2022-04-13

CVE-2022-22960: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support…

PriorityP184high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-06
Exploited in the wild
EPSS
37.17%
98.4th percentile
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.

Affected

11 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation>= 3.0 < 5.05.0
vmwareidentity_manager
vmwareidentity_manager
vmwareidentity_manager
vmwareidentity_manager
vmwarevrealize_automation
vmwarevrealize_suite_lifecycle_manager>= 8.0 < 9.09.0
vmwareworkspace_one_access
vmwareworkspace_one_access
vmwareworkspace_one_access
vmwareworkspace_one_access

Detection & IOCsextracted from sources · hover to see the quote

filenamecertproxyService.sh
  • Monitor for privilege escalation to root from UID 1001 (horizon user) on VMware Workspace ONE Access, Identity Manager, or vRealize Automation appliances.
  • Alert on unexpected permission changes (chmod/chown) to certproxyService.sh on affected VMware appliances, as exploitation involves overwriting its permissions.
  • CVE-2022-22960 was confirmed exploited in the wild by VMware; monitor for chained exploitation alongside CVE-2022-22954 (server-side template injection RCE) as threat actors combined these vulnerabilities to gain full system control.
  • Investigate any process running as the 'horizon' user (UID 1001) that spawns a root shell or modifies support scripts on VMware appliances.
  • ·Exploitation requires local access (UID 1001 / horizon user); this is a post-exploitation or chained-attack vector, not a standalone remote exploit. Prioritize detection of prior-stage RCE (e.g., CVE-2022-22954) that may deliver local access.
  • ·Affected product versions: VMware Workspace ONE Access Appliance 21.08.0.1, 21.08.0.0, 20.10.0.1, 20.10.0.0; VMware Identity Manager Appliance 3.3.6, 3.3.5, 3.3.4, 3.3.3; VMware vRealize Automation 7.6. vSphere and Workspace ONE Access/vIDM connectors are NOT affected.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.