{"cveID":"CVE-2022-22948","vendorProject":"VMware","product":"vCenter Server","vulnerabilityName":"VMware vCenter Server Incorrect Default File Permissions Vulnerability ","dateAdded":"2024-07-17","shortDescription":"VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information.","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2024-08-07","knownRansomwareCampaignUse":"Unknown","notes":"https://www.vmware.com/security/advisories/VMSA-2022-0009.html;  https://nvd.nist.gov/vuln/detail/CVE-2022-22948","cwes":["CWE-276"],"year":2022,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2022-22948","technique":"T1078","technique_name_at_mapping":"Valid Accounts","mapping_type":"exploitation_technique","capability_group":"default_cfg","comments":"This vulnerability is exploited by an adversary who has gained access to a valid account on the vCenter Server. The adversary can gain access to unencrypted Postgres credentials on the server, which grants the adversary access to the vCenter's internal database where the vpxuser account passphrase is stored. Adversaries can leverage this information to decrypt the vpxuser password, which will grant them root privileges. ","references":["https://pentera.io/blog/information-disclosure-in-vmware-vcenter/","https://cloud.google.com/blog/topics/threat-intelligence/vmware-esxi-zero-day-bypass/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-22948","technique":"T1068","technique_name_at_mapping":"Exploitation for Privilege Escalation","mapping_type":"secondary_impact","capability_group":"default_cfg","comments":"This vulnerability is exploited by an adversary who has gained access to a valid account on the vCenter Server. The adversary can gain access to unencrypted Postgres credentials on the server, which grants the adversary access to the vCenter's internal database where the vpxuser account passphrase is stored. Adversaries can leverage this information to decrypt the vpxuser password, which will grant them root privileges. ","references":["https://pentera.io/blog/information-disclosure-in-vmware-vcenter/","https://cloud.google.com/blog/topics/threat-intelligence/vmware-esxi-zero-day-bypass/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-22948","technique":"T1212","technique_name_at_mapping":"Exploitation for Credential Access","mapping_type":"primary_impact","capability_group":"default_cfg","comments":"This vulnerability is exploited by an adversary who has gained access to a valid account on the vCenter Server. The adversary can gain access to unencrypted Postgres credentials on the server, which grants the adversary access to the vCenter's internal database where the vpxuser account passphrase is stored. Adversaries can leverage this information to decrypt the vpxuser password, which will grant them root privileges. ","references":["https://pentera.io/blog/information-disclosure-in-vmware-vcenter/","https://cloud.google.com/blog/topics/threat-intelligence/vmware-esxi-zero-day-bypass/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1068","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation for Privilege Escalation","name_at_mapping":"Exploitation for Privilege Escalation","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":31,"has_detection_strategy":true},{"id":"T1078","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Valid Accounts","name_at_mapping":"Valid Accounts","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":56,"has_detection_strategy":true},{"id":"T1212","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation for Credential Access","name_at_mapping":"Exploitation for Credential Access","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":5,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}