Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-22952


VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface may be able to execute code on the Windows instance where AppC Server is installed by uploading a specially crafted file.


Published

2022-03-23T20:15:10.840

Last Modified

2024-11-21T06:47:40.390

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.1 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application vmware carbon_black_app_control < 8.5.14 Yes
Application vmware carbon_black_app_control < 8.6.6 Yes
Application vmware carbon_black_app_control < 8.7.4 Yes
Application vmware carbon_black_app_control < 8.8.2 Yes
Operating System microsoft windows - No

References