PT-2022-28015 · Vmware · Vsphere

Di1L0O

·

Published

2022-12-14

·

Updated

2025-04-21

·

CVE-2022-46996

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vSphere selfuse version 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749
Description The issue allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges via a code execution backdoor in the request package.
Recommendations For version 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749, consider restricting access to the request package to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Hidden Functionality

Weakness Enumeration

Related Identifiers

CVE-2022-46996

Affected Products

Vsphere