CVE-2022-22952
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface may be able to execute code on the Windows instance where AppC Server is installed by uploading a specially crafted file.
VMware Carbon Black App Control (versiones 8.5.x anteriores a 8.5.14, versiones 8.6.x anteriores a 8.6.6, versiones 8.7.x anteriores a 8.7.4 y versiones 8.8.x anteriores a 8.8.2) contiene una vulnerabilidad de carga de archivos. Un actor malicioso con acceso administrativo a la interfaz de administración de VMware App Control puede ser capaz de ejecutar código en la instancia de Windows donde está instalado AppC Server al cargar un archivo especialmente diseñado
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-10 CVE Reserved
- 2022-03-23 CVE Published
- 2023-09-03 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.vmware.com/security/advisories/VMSA-2022-0008.html | 2022-03-31 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vmware Search vendor "Vmware" | Carbon Black App Control Search vendor "Vmware" for product "Carbon Black App Control" | >= 8.5 < 8.5.14 Search vendor "Vmware" for product "Carbon Black App Control" and version " >= 8.5 < 8.5.14" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Vmware Search vendor "Vmware" | Carbon Black App Control Search vendor "Vmware" for product "Carbon Black App Control" | >= 8.6 < 8.6.6 Search vendor "Vmware" for product "Carbon Black App Control" and version " >= 8.6 < 8.6.6" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Vmware Search vendor "Vmware" | Carbon Black App Control Search vendor "Vmware" for product "Carbon Black App Control" | >= 8.7.0 < 8.7.4 Search vendor "Vmware" for product "Carbon Black App Control" and version " >= 8.7.0 < 8.7.4" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Vmware Search vendor "Vmware" | Carbon Black App Control Search vendor "Vmware" for product "Carbon Black App Control" | >= 8.8.0 < 8.8.2 Search vendor "Vmware" for product "Carbon Black App Control" and version " >= 8.8.0 < 8.8.2" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|