vulnerability

vCenter Server improper permission local privilege escalation vulnerabilities (VMSA-2021-0020) (CVE-2021-22015)

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Sep 21, 2021
Added
Jan 21, 2022
Modified
Jan 24, 2022

Description

The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their privileges to root on vCenter Server Appliance.

Solution

vmware-vcenter-cve-2021-22015-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.