CVE-2021-22042
16.02.2022, 17:15
VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user.Enginsight
Vendor | Product | Version |
---|---|---|
vmware | cloud_foundation | 4.0 ≤ 𝑥 < 4.4 |
vmware | esxi | 7.0:update_1 |
vmware | esxi | 7.0:update_2 |
vmware | esxi | 7.0:update_3 |
𝑥
= Vulnerable software versions