Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2021-22048

Description

The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group.

POC

Reference

- http://packetstormsecurity.com/files/167733/VMware-Security-Advisory-2022-0025.2.html

- http://packetstormsecurity.com/files/167795/VMware-Security-Advisory-2021-0025.3.html

Github

- https://github.com/ARPSyndicate/cvemon