- Description
- VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.
- Source
- security@vmware.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
Data from CISA
- Vulnerability name
- VMware Multiple Products Privilege Escalation Vulnerability
- Exploit added on
- Apr 15, 2022
- Exploit action due
- May 6, 2022
- Required action
- Apply updates per vendor instructions.
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5071E0B4-FE4B-4525-BAF6-3900D9C8D48D",
"versionEndExcluding": "5.0",
"versionStartIncluding": "3.0"
},
{
"criteria": "cpe:2.3:a:vmware:identity_manager:3.3.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "97D98937-489B-4AA5-B99E-9AB639C582CA"
},
{
"criteria": "cpe:2.3:a:vmware:identity_manager:3.3.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E93CB5E-CB4A-474A-9901-2E098928C489"
},
{
"criteria": "cpe:2.3:a:vmware:identity_manager:3.3.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A215A7D-F644-41DE-AB4E-69145DA48F9F"
},
{
"criteria": "cpe:2.3:a:vmware:identity_manager:3.3.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5EBB8190-2101-4EE5-844E-B46E7FB78FD7"
},
{
"criteria": "cpe:2.3:a:vmware:vrealize_automation:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "370EF5F6-77E2-4EF7-9148-9DA5C52E50F5",
"versionEndExcluding": "9.0",
"versionStartIncluding": "8.0"
},
{
"criteria": "cpe:2.3:a:vmware:vrealize_automation:7.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "471BB5AF-3744-45FE-937D-BBEC421035EB"
},
{
"criteria": "cpe:2.3:a:vmware:vrealize_suite_lifecycle_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FC19367B-D2F8-4966-BE2F-12700C9337EC",
"versionEndExcluding": "9.0",
"versionStartIncluding": "8.0"
},
{
"criteria": "cpe:2.3:a:vmware:workspace_one_access:20.10.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "639F6029-DE62-49BD-A767-C5D499389C37"
},
{
"criteria": "cpe:2.3:a:vmware:workspace_one_access:20.10.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88AD029C-7707-4F1E-BE7F-2DE27D384538"
},
{
"criteria": "cpe:2.3:a:vmware:workspace_one_access:21.08.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57375AD7-8042-472F-B49E-653C77EAFA48"
},
{
"criteria": "cpe:2.3:a:vmware:workspace_one_access:21.08.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC3DC465-1FA7-4F5B-9A9A-12F8FB4CE146"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]