IRONSMITHINTEL
HIGHCVSS7.8
|
Actively Exploited
|CISA KEV|CVE-2022-22960|Auth: low — authenticated user|Reboot: required|Manual only

VMware Multiple Products Privilege Escalation Vulnerability

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.

Published Apr 13, 2022 · Updated May 16, 2026
Why patchRisk explained in plain English
Worst-case scenarioIf unpatched

A local attacker, with a low-privilege account, can achieve full data confidentiality loss, arbitrary modification of data, complete denial of service or system unavailability. Federal agencies are required to remediate by 2022-05-06 under CISA BOD 22-01.

How the attack worksNo clicks needed

This is a Incorrect Permission Assignment (CWE-732) vulnerability in VMware Multiple Products. VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'. Exploitation requires local access, low attack complexity, a low-privilege authenticated account, and no user interaction required.

Am I affected?Quick check

Probably yes if any of these apply:

Virtualisation Administrators
Infrastructure Team
IT Security
Running cloud foundation: 3.0 ≤ v < 5.0; identity manager: 3.3.3, 3.3.4, 3.3.5, 3.3.6; vrealize automation: 7.6; vrealize suite lifecycle manager: 8.0 ≤ v < 9.0; workspace one access: 20.10.0.0, 20.10.0.1, 21.08.0.0, 21.08.0.1
Real-world incidentsWhat we've seen

Active exploitation documented in the wild. Threat-research write-up: http://packetstormsecurity.com/files/171918/Mware-Workspace-ONE-Remote-Code-Execution.html

How to patch

Manual remediation steps

Apply the Vendor Patch

This vulnerability is in the CISA Known Exploited Vulnerabilities catalog — apply the vendor's security update as soon as possible.

CISA required action: Apply updates per vendor instructions.

References

    1
    Vendor advisory: https://www.vmware.com/security/advisories/VMSA-2022-0011.html
    1
    NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2022-22960
    1
    CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22960
PowerShell automationComing soon

No tested PowerShell script for this entry yet. We’re prioritising automation based on user demand.