Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-31660.
PoCs published by Spencer McIntyre, including Metasploit module exploits/linux/local/vmware_workspace_one_access_certproxy_lpe.
AI-analyzed exploit summary This Metasploit module exploits CVE-2022-31660, a local privilege escalation vulnerability in VMware Workspace ONE Access. It allows the 'horizon' user to escalate to root by modifying a service script and restarting the vmware-certproxy service via sudo.
Description
VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
Exploits (1)
This Metasploit module exploits CVE-2022-31660, a local privilege escalation vulnerability in VMware Workspace ONE Access. It allows the 'horizon' user to escalate to root by modifying a service script and restarting the vmware-certproxy service via sudo.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H