CVE-2021-22048

CVSSv3 Range7.1
Issue Date2021-11-10
Updated On2022-12-15
CVE(s)CVE-2021-22048
SynopsisVMware vCenter Server updates address a privilege escalation vulnerability.
[Important]

Impacted Products

  • VMware vCenter Server (vCenter Server)
  • VMware Cloud Foundation (Cloud Foundation)

Known Attack Vectors

A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group.

Workarounds

Workaround for CVE-2021-22048 is to switch to AD over LDAPS authentication OR Identity Provider Federation for AD FS (vSphere 7.0 or later) from Integrated Windows Authentication (IWA) as documented in the KB listed in the ‘Workarounds’ column of the ‘Response Matrix’ below.


Resolution

Fixes for CVE-2021-22048 are documented in the ‘Fixed Version‘ column of the ‘Response Matrix‘ below.

Impacted ProductsFıxed VersIonWorkarounds
vCenter Server 8.08.0aKB86292
vCenter Server 7.07.0 U3iKB86292
vCenter Server 6.77.0 U3iKB86292
vCenter Server 6.57.0 U3iKB86292
Cloud Foundation | vCenter Server 4.xKB90336KB86292
Cloud Foundation | vCenter Server 3.xKB90336KB86292
Response Matrix

Reference

Similar Posts

Bir yanıt yazın

E-posta adresiniz yayınlanmayacak. Gerekli alanlar * ile işaretlenmişlerdir