EXPOSURES › CVE-2022-22960
CVE-2022-22960
HIGH ⌖ ON CISA KEV · EXPLOITEDVMware Workspace ONE Access, Identity Manager, and vRealize Automation suffered a privilege escalation vulnerability due to improper permissions in support scripts.
This privilege escalation flaw allowed attackers to escalate privileges within VMware products, potentially leading to unauthorized access or data exfiltration. DIB organizations must ensure these products are patched immediately, as unpatched vulnerabilities are a primary compliance failure under NIST 800-171. The failure highlights the risk of relying on support scripts without proper permission controls.
Shame score — A known privilege escalation vulnerability in widely deployed enterprise products that was actively exploited in the KEV catalog, indicating a failure to patch known issues.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |