kevmap

Coverage › CVE-2022-22960

CVE-2022-22960 Mapped Sigma

VMware Multiple Products Privilege Escalation Vulnerability

Vendor / product
VMware — Multiple Products
Description (CISA)
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.
Added to KEV
2022-04-15
Due date
2022-05-06
Required action
Apply updates per vendor instructions.
Known ransomware use
Unknown
CWE
CWE-250
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2022-22960
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28

1 mapping object across 1 technique. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such.

TechniqueMapping typeCTID commentStatus in v19.2
T1222 File and Directory Permissions Modification exploitation technique This vulnerability allows adversaries with local access to escalate privileges to root. Adversaries have been observed chaining this following exploit of CVE-2022-22954.
ref 1
live

Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources

T1222 File and Directory Permissions Modification exploitation technique

Sigma rules tagged attack.t1222 (2)

Author: frack113, Nasreddine Bencherchali (Nextron Systems) · 2023-07-18 · logsource: product=windows category=ps_script · 3bf1d859-3a7e-44cb-8809-a99e066d3478
Detects PowerShell scripts to set the ACL to a file in the Windows folder
Techniques: T1222
Author: frack113, Nasreddine Bencherchali (Nextron Systems) · 2023-07-18 · logsource: product=windows category=ps_script · cae80281-ef23-44c5-873b-fd48d2666f49
Detects PowerShell scripts set ACL to of a file or a folder
Techniques: T1222