LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-22960: VMware Multiple Products Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 15, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 6, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-22960 to its Known Exploited Vulnerabilities catalog on Apr 15, 2022, with a federal patch deadline of May 6, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.

CVE-2022-22960 is a privilege escalation vulnerability affecting multiple VMware products, specifically Workspace ONE Access, Identity Manager, and vRealize Automation. It stems from improper permissions in support scripts, which can allow an attacker who already has some level of access to gain higher privileges on the system. For IT and security teams, this matters because these products often sit in identity and automation paths; successful escalation can expand an attacker’s control over authentication, orchestration, or adjacent infrastructure.

CISA lists the required action as applying updates per vendor instructions. Known ransomware use is not documented for this CVE. Confirm all product names, fixed builds, and deployment-specific guidance against the official VMware advisory before acting.

How it works

The weakness is classified as CWE-250 (Execution with Unnecessary Privileges). In plain terms, support scripts shipped with the affected products run or are reachable under permissions that are broader than required. An attacker who can already interact with the host or application—through a lower-privileged account, a compromised service identity, or another foothold—can abuse those overly permissive scripts to perform actions or obtain rights they should not have.

Exact exploit mechanics, preconditions, and attack chains are not detailed in the provided facts. Treat this as a local or authenticated privilege-escalation issue typical of mis-permissioned administrative or support tooling. Do not assume remote unauthenticated exploitation unless the vendor advisory explicitly states it. Always validate the attack surface and required access level against VMware’s advisory for your exact product and version.

Am I affected? How to find it in your systems

These components commonly appear in enterprise identity, workspace, and cloud-automation environments. Workspace ONE Access and Identity Manager often front single sign-on and directory integration; vRealize Automation is used for infrastructure and application provisioning. They may run as appliances, virtual machines, or integrated services in data centers or private clouds.

If public detail on exact vulnerable builds is limited in your environment’s records, treat any unpatched instance of the named products as in-scope until confirmed otherwise against the advisory.

How to remediate

Patch first. Apply the updates VMware released for the affected products exactly as described in the vendor advisory and follow CISA’s direction to apply updates per vendor instructions. Schedule maintenance windows that cover all instances, including non-production systems that share credentials or network trust with production.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls focused on limiting who can reach the vulnerable components and what those components can do.

These measures lower risk but do not replace the patch. Track the exception and remediate as soon as operationally feasible.

If your data may have been exposed

Actively exploited privilege-escalation flaws can lead to broader compromise of identity systems and the environments they control. If you have evidence of exploitation or cannot rule it out, follow your incident-response plan: isolate affected hosts, preserve logs and disk images, rotate credentials and secrets that the products could access, and assess downstream impact on directories and automated workloads. Known ransomware use is not documented for this CVE; still treat any confirmed intrusion seriously. As a routine check, users can run a free exposure scan of their email addresses against known breach data sets to see whether associated credentials have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVMware · Multiple Products
WeaknessCWE-250
Added to CISA KEVApr 15, 2022
Federal patch deadlineMay 6, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities