CISA Known Exploited Vulnerability

CVE-2022-22960

VMware · Multiple Products

VMware Multiple Products Privilege Escalation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-250
Ransomware Unknown

CISA description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.

Required action

Apply updates per vendor instructions.