VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user.
2022-02-16T17:15:10.537
2024-11-21T05:49:29.300
Modified
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | cloud_foundation | < 4.4 | Yes |
Operating System | vmware | esxi | 7.0 | Yes |
Operating System | vmware | esxi | 7.0 | Yes |
Operating System | vmware | esxi | 7.0 | Yes |