CVE-2021-22048
10.11.2021, 18:15
The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group.Enginsight
Vendor | Product | Version |
---|---|---|
vmware | cloud_foundation | 3.0 ≤ 𝑥 ≤ 3.10.2.2 |
vmware | vcenter_server | 6.5 |
vmware | vcenter_server | 6.7 |
vmware | vcenter_server | 7.0 |
vmware | cloud_foundation | 4.0 ≤ 𝑥 ≤ 4.1.0.1 |
𝑥
= Vulnerable software versions
References