vulnerability
vCenter Server improper permission local privilege escalation vulnerabilities (VMSA-2021-0020) (CVE-2021-22015)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:L/Au:N/C:C/I:C/A:C) | Sep 21, 2021 | Jan 21, 2022 | Jan 24, 2022 |
Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Sep 21, 2021
Added
Jan 21, 2022
Modified
Jan 24, 2022
Description
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their privileges to root on vCenter Server Appliance.
Solution
vmware-vcenter-cve-2021-22015-upgrade-latest
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.