CVE-2022-22960

HIGH(7.8)KEVElevated Risk

VMware Multiple Products Privilege Escalation Vulnerability

Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.

KEV Information

Vendor
VMware
Product
Multiple Products
Date Added
April 15, 2022
Due Date
May 6, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
vmwarecloud foundation>= 3.0, < 5.0
vmwareidentity manager3.3.3; 3.3.4; 3.3.5; 3.3.6
vmwarevrealize automation7.6
vmwarevrealize suite lifecycle manager>= 8.0, < 9.0
vmwareworkspace one access20.10.0.0; 20.10.0.1; 21.08.0.0; 21.08.0.1

Multiple CVSS Assessments

Source: [email protected](Primary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

CVSS Score

7.8
HIGH(7.8)

EPSS Score

EPSS Score37.17%
EPSS Percentile98.4%

Dates

PublishedApril 13, 2022
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.