CVE-2021-22042
16.02.2022, 17:15
VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user.Enginsight
| Vendor | Product | Version |
|---|---|---|
| vmware | cloud_foundation | 4.0 ≤ 𝑥 < 4.4 |
| vmware | esxi | 7.0:update_1 |
| vmware | esxi | 7.0:update_2 |
| vmware | esxi | 7.0:update_3 |
𝑥
= Vulnerable software versions