CVE-2021-22042

EUVD-2021-9211
VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
Affected Products (NVD)
VendorProductVersion
vmwarecloud_foundation
4.0 ≤
𝑥
< 4.4
vmwareesxi
7.0:update_1
vmwareesxi
7.0:update_2
vmwareesxi
7.0:update_3
𝑥
= Vulnerable software versions