ZeroHour

CVE-2022-22948

KEVmass

Information Disclosure via Incorrect File Permissions in VMware vCenter Server

CISA: VMware vCenter Server Incorrect Default File Permissions Vulnerability

CVSS 3.1
6.5 medium
EPSS
13%p96
Published
()
KEV added
AI analysis

VMware vCenter Server ships certain files with incorrectly permissive default file permissions, creating an information disclosure vulnerability (CWE-276). A malicious actor with non-administrative (low-privileged) network access to the vCenter Server can exploit the misconfigured permissions to read sensitive information; per the CVSS vector there is confidentiality impact only, with no integrity or availability effect. Any organization running VMware vCenter Server, or VMware Cloud Foundation whose vCenter Server component is affected, is exposed to the flaw. CISA added the bug to its Known Exploited Vulnerabilities catalog on 2024-07-17, indicating exploitation in the wild, and EPSS currently assigns a 13.3% probability of exploitation within 30 days (96th percentile); no public proof-of-concept is known.

What to do: Upgrade vCenter Server and the vCenter Server component of Cloud Foundation to the fixed releases cited in VMware's advisory for CVE-2022-22948, per the CISA KEV required action (or discontinue use if patching is unavailable). Given the KEV listing and headlines describing stealthy VMware-focused activity by UNC3886, prioritize internet-exposed and high-value vCenter deployments, review which non-administrative accounts can reach the vCenter appliance, and monitor those accounts and vCenter logs for signs of unauthorized file access.

Affected
VMware vCenter Server
VMware Cloud Foundation (vCenter Server component)
Estimated exposure
masshundreds of thousands of vCenter Server instances worldwide, with tens of thousands exposed directly to the internet per public scans — vSphere/vCenter holds a dominant share of enterprise virtualization and vCenter is its standard management server, so the installed base plausibly exceeds 100,000 instances, although exploitation here requires low-privileged access to the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.

CISA Known Exploited Vulnerability
Affected
VMware vCenter Server
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
vmware
Products
cloud foundation, vcenter server
Weakness
CWE-276
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news