Skip to main content

CVE detail

CVE-2022-22972

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

CVSS 9.8 · CriticalBuzz score 49.4

Buzz score

Why this CVE is surfacing

Buzz score total 49.4

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 29.4 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
29.4
18 evidence mentions in the snapshot
Diversity score
20.0
7 sources across 3 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
18 source links · newest first
  • VMware has released fixes for ten vulnerabilities, including CVE-2022-31656, an authentication bypass vulnerability affecting VMware Workspace ONE Access, Identity Manager and vRealize Automation, which the company considers critical and advises to patch or mitigate immediately. While there is no indication that any of these flaws is currently being leveraged by attackers in the wild, the security researcher who reported CVE-2022-31656 is planning to release a technical writeup and a POC “soon”. About CVE-2022-31656 CVE-2022-31656 is … More →

    newswww.helpnetsecurity.comAug 3, 2022, 9:29 AM
  • 30th May – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 30th May, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research reported how the Conti ransom group has taken cybercrime to a new, geopolitical level. They intervene in the internal politics of Costa Rica, the relationship between Costa Rica and […]

    vendorresearch.checkpoint.comMay 30, 2022, 4:50 PM
  • A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs for free in your email box. If you want to also receive for free the newsletter with the international press subscribe here. Experts believe that Russian Gamaredon APT could fuel a new round of DDoS attacks The […]

    newssecurityaffairs.comMay 29, 2022, 2:33 PM
  • SecurityWeek: 05/27/22 Penetration testing company Horizon3.ai on Thursday published a technical deep dive for CVE-2022-22972 and made public a PoC exploit. VMware has updated its initial advisory to inform customers about the availability of a PoC, which further increases the chances of exploitation. Read the entire article here

    exploithorizon3.aiMay 27, 2022, 7:47 PM
  • The Horizon3.ai Attack Team released their VMware Authentication Vulnerability (CVE-2022-22972) Technical Deep Dive.

    exploithorizon3.aiMay 27, 2022, 6:48 PM
  • When VMware announced patches for a critical vulnerability on May 18, users were warned that exploitation in the wild would likely start soon, and now a proof-of-concept (PoC) exploit targeting the flaw has been made public.

    newswww.securityweek.comMay 27, 2022, 6:15 PM
  • Security researchers released PoC exploit code for the critical authentication bypass vulnerability CVE-2022-22972 affecting multiple VMware products. Horizon3 security researchers have released a proof-of-concept (PoC) exploit and technical analysis for the critical authentication bypass vulnerability CVE-2022-22972 affecting multiple VMware products. The virtualization giant recently warned that a threat actor can exploit the CVE-2022-22972 flaw (CVSSv3 base score of 9.8) […]

    newssecurityaffairs.comMay 27, 2022, 5:58 AM
  • VMware recently patched a critical authentication bypass vulnerability in their VMware Workspace ONE Access, Identity Manager and vRealize Automation products (CVE-2022-22972). This vulnerability allows an attacker to login as any known local user.

    exploithorizon3.aiMay 26, 2022, 1:37 PM
  • The Stack: 05/25/22 Now the security team at San Francisco-based company Horizon3 say that they have successful reproduced exploitation of CVE-2022-22972 affecting multiple VMware products such as Workspace ONE with security researcher James Horseman at the company expected to share a technical writeup and proof-of-concept (POC) shortly. Read the entire article here

    exploithorizon3.aiMay 25, 2022, 8:01 PM
  • 23rd May – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 23rd May, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has unveiled a targeted cyber-espionage operation against at least two research institutes in Russia, which are part of the Rostec Corporation, a state-owned defense conglomerate. The sophisticated campaign, which […]

    vendorresearch.checkpoint.comMay 23, 2022, 1:28 PM
  • A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs for free in your email box. If you want to also receive for free the newsletter with the international press subscribe here. Asian media company Nikkei suffered a ransomware attack Russia-linked Sandworm continues to conduct attacks against […]

    newssecurityaffairs.comMay 22, 2022, 5:32 PM
  • Here’s an overview of some of last week’s most interesting news, articles and interviews: Kali Linux 2022.2 released: Desktop enhancements, tweaks for the terminal, new tools, and more! Offensive Security has released Kali Linux 2022.2, the latest version of its popular penetration testing and digital forensics platform. VMware issues critical fixes, CISA orders federal agencies to act immediately (CVE-2022-22972) VMware has released patches for a privately reported critical vulnerability (CVE-2022-22972) in VMware’s Workspace ONE Access, … More →

    newswww.helpnetsecurity.comMay 22, 2022, 8:30 AM
  • CVE-2022-22954, one of several recently published VMware vulnerabilities, is being exploited in the wild. Read our observations and recommendations.

    vendorunit42.paloaltonetworks.comMay 20, 2022, 1:00 PM
  • The U.S. Cybersecurity and Infrastructure Agency (CISA) has issued an emergency directive over two new vulnerabilities in VMware products. According to the advisory, threat actors are likely to exploit CVE-2022-22972 and CVE-2022-22973 in several products including VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM), VMware vRealize Automation (vRA), VMware Cloud Foundation, and vRealize Suite […]

    newswww.csoonline.comMay 19, 2022, 1:10 PM
  • The US Cybersecurity and Infrastructure Security Agency (CISA) has warned organizations about two actively exploited VMware product vulnerabilities, and the agency believes two other freshly patched flaws will also be exploited soon.

    newswww.securityweek.comMay 19, 2022, 9:57 AM
  • VMware has released patches for a privately reported critical vulnerability (CVE-2022-22972) in VMware’s Workspace ONE Access, VMware Identity Manager (vIDM), vRealize Lifecycle Manager, vRealize Automation, and VMware Cloud Foundation products, and is urging administrators to patch or mitigate immediately, because “the ramifications of this vulnerability are serious.” Simultaneously, the Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive for all federal civilian executive branch agencies, which are ordered to enumerate all instances of … More →

    newswww.helpnetsecurity.comMay 19, 2022, 9:25 AM
  • CISA orders federal agencies to fix VMware CVE-2022-22972 and CVE-2022-22973 vulnerabilities by May 23, 2022. The Cybersecurity and Infrastructure Security Agency (CISA) issued the Emergency Directive 22-03 to order federal agencies to fix VMware CVE-2022-22972 and CVE-2022-22973 flaws or to remove the affected products from their networks by May 23, 2022. The list of impacted […]

    newssecurityaffairs.comMay 19, 2022, 6:13 AM
  • VMware addressed a critical authentication bypass vulnerability “affecting local domain users” in multiple products. The virtualization giant warns that a threat actor can exploit the flaw, tracked as CVE-2022-22972 (CVSSv3 base score of 9.8), to obtain admin privileges and urges customers to install patches immediately. “This critical vulnerability should be patched or mitigated immediately per the […]

    newssecurityaffairs.comMay 18, 2022, 9:29 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence