CVE-2022-22951

CRITICAL

VMware Carbon Black App Control 8.5-8.8.1 - Authenticated RCE via Input Validation

Title source: llm
STIX 2.1

Description

VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute commands on the server due to improper input validation leading to remote code execution.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://www.vmware.com/security/advisories/VMSA-2022-0008.html

Scores

CVSS v3 9.1
EPSS 0.0271
EPSS Percentile 86.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
vmware/carbon_black_app_control 8.5 - 8.5.14
Published Mar 23, 2022
Tracked Since Feb 18, 2026