VYPR
Unrated severityNVD Advisory· Published May 20, 2022· Updated Aug 3, 2024

CVE-2022-22973

CVE-2022-22973

Description

VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A local privilege escalation vulnerability in VMware Workspace ONE Access and Identity Manager allows attackers with local access to gain root privileges.

Vulnerability

The vulnerability, identified in VMware Workspace ONE Access and Identity Manager, allows a malicious actor with local access to escalate privileges to root. This affects VMware Workspace ONE Access (version unspecified in the reference) and VMware Identity Manager (version unspecified) as per VMSA-2022-0014 [1].

Exploitation

An attacker must have local access to the affected system. No additional authentication or user interaction is required beyond local access. The attack vector is local, meaning the attacker must be able to execute commands or run code on the target machine. The specific steps are not detailed in the reference, but the advisory confirms that local access is sufficient to trigger the privilege escalation [1].

Impact

Successful exploitation allows the attacker to escalate privileges to the root user, gaining full administrative control over the affected system. This results in complete compromise of confidentiality, integrity, and availability of the system [1].

Mitigation

VMware has released patches to remediate this vulnerability. The advisory VMSA-2022-0014.1 (updated on 2022-05-27) provides patching guidance for affected products including VMware Workspace ONE Access, Identity Manager, and vRealize Automation. Users should apply the latest updates from VMware. No workaround is mentioned in the reference [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.