CVE-2022-21980

Vulnerability updated a month ago (2024-11-29T14:22:04.258Z)
Download STIX
Preview STIX
CVE-2022-21980 is a vulnerability in VMware's vCenter Server. The flaw allows an attacker to execute arbitrary code with elevated privileges on affected systems. This could allow an attacker to gain complete control over the targeted system, compromise sensitive data, or launch further attacks against other systems within the network. The vulnerability was discovered and reported to VMware by security researchers at Positive Technologies. It received a CVSSv3 score of 9.8 out of 10, indicating a critical severity level. VMware released a patch for the vulnerability on March 3, 2022, with a recommendation that users should apply the patch as soon as possible. As with any software vulnerability, prompt action is necessary to mitigate the risk of exploitation. Organizations that use vCenter Server should ensure that they have applied the security patch provided by VMware. Additionally, it is recommended that organizations regularly monitor their IT infrastructure for any signs of unauthorized access or suspicious activity, and implement security best practices such as least privilege access, network segmentation, and strong password policies to reduce the risk of a successful attack.
Description last updated: 2023-06-23T12:57:43.456Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the CVE-2022-21980 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more