VYPR
Unrated severityNVD Advisory· Published Aug 5, 2022· Updated Aug 3, 2024

CVE-2022-31664

CVE-2022-31664

Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2022-31664 is a privilege escalation vulnerability in VMware Workspace ONE Access, Identity Manager, and vRealize Automation allowing local attackers to gain root privileges.

Vulnerability

CVE-2022-31664 is a privilege escalation vulnerability affecting VMware Workspace ONE Access, Identity Manager, and vRealize Automation. The bug resides in a privileged component of these products and can be triggered by a local attacker without requiring elevated privileges. The vulnerability affects versions prior to the fixed releases detailed in the VMware advisory VMSA-2022-0021 [1].

Exploitation

An attacker with local access to an affected system can exploit this vulnerability to escalate privileges to root. No user interaction or additional authentication is required beyond initial local system access. The exact exploitation steps are not publicly disclosed but rely on the local attacker's ability to execute code or manipulate system resources.

Impact

Successful exploitation allows the attacker to gain full root privileges on the affected system, leading to complete compromise of the host. This includes the ability to read, modify, or delete any data, install software, and create new accounts with unrestricted access. The confidentiality, integrity, and availability of the system are all at risk.

Mitigation

VMware released security updates addressing this vulnerability on August 2, 2022, as part of VMSA-2022-0021 [1]. Affected users should apply the latest patches for their respective products (Workspace ONE Access, Identity Manager, and vRealize Automation) immediately. No workarounds are available; upgrading to the fixed versions is the only mitigation. The advisory does not list CVE-2022-31664 in the CISA Known Exploited Vulnerabilities catalog as of the update.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.