Description
VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
Exploits (1)
metasploit
WORKING POC
GREAT
by Spencer McIntyre · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/vmware_workspace_one_access_certproxy_lpe.rb
Scores
CVSS v3
7.8
EPSS
0.0336
EPSS Percentile
87.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (12)
vmware/access_connector
21.08.0.0
vmware/access_connector
21.08.0.1
vmware/access_connector
22.05
vmware/identity_manager
3.3.4
vmware/identity_manager
3.3.5
vmware/identity_manager
3.3.6
vmware/identity_manager_connector
3.3.4
vmware/identity_manager_connector
3.3.5
vmware/identity_manager_connector
3.3.6
vmware/identity_manager_connector
19.03.0.1
... and 2 more
Published
Aug 05, 2022
Tracked Since
Feb 18, 2026