VYPR
Unrated severityNVD Advisory· Published Aug 5, 2022· Updated Aug 3, 2024

CVE-2022-31660

CVE-2022-31660

Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A local privilege escalation in VMware Workspace ONE Access, Identity Manager, and vRealize Automation allows an attacker with local access to gain root privileges.

Vulnerability

CVE-2022-31660 is a privilege escalation vulnerability in VMware Workspace ONE Access, Identity Manager, and vRealize Automation. The vulnerability allows a malicious actor with local access to the affected system to escalate privileges to root. The advisory [1] indicates this issue affects multiple VMware products and is part of a larger set of vulnerabilities patched in the August 2022 update bundle (VMSA-2022-0021). Exact affected versions are detailed in the VMware advisory [1].

Exploitation

Exploitation requires the attacker to have local access to the impacted system. No additional authentication or user interaction is mentioned. The attacker must be able to execute code or commands locally on the vulnerable appliance. The advisory [1] does not provide a detailed exploit sequence, but the vulnerability is classified as a privilege escalation, meaning the attacker can leverage existing local access to gain higher privileges.

Impact

Successful exploitation allows an attacker with local access to elevate their privileges to root, the highest level of access on the system. This grants full control over the affected appliance, enabling the attacker to perform any action, including reading, modifying, or deleting sensitive data and system configurations.

Mitigation

VMware has released patches to address CVE-2022-31660 as part of the VMSA-2022-0021 advisory [1]. The fixed versions are listed in the advisory. Users should immediately update their deployments to the latest supported versions. No workarounds are provided in the advisory [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.