Coverage › CVE-2022-22960
CVE-2022-22960 Mapped Sigma
VMware Multiple Products Privilege Escalation Vulnerability
- Vendor / product
- VMware — Multiple Products
- Description (CISA)
- VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.
- Added to KEV
- 2022-04-15
- Due date
- 2022-05-06
- Required action
- Apply updates per vendor instructions.
- Known ransomware use
- Unknown
- CWE
- CWE-250
- CISA notes
- https://nvd.nist.gov/vuln/detail/CVE-2022-22960
- Elsewhere
- cve.org · NVD · CISA KEV · JSON
ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28
1 mapping object across 1 technique. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such.
| Technique | Mapping type | CTID comment | Status in v19.2 |
|---|---|---|---|
| T1222 File and Directory Permissions Modification | exploitation technique | This vulnerability allows adversaries with local access to escalate privileges to root. Adversaries have been observed chaining this following exploit of CVE-2022-22954. ref 1 |
live |
Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources
T1222 File and Directory Permissions Modification exploitation technique
- DET0299 Multi-Platform File and Directory Permissions Modification Detection Strategy
AN0834 WindowsSequential behavioral chain of privilege escalation through permission modification: (1) Process creation of permission-modifying utilities (icacls, takeown, attrib, cacls), (2) Correlation with unusual user context or timing, (3) DACL modification events targeting sensitive files/directories, (4) Subsequent file access or modification attempts indicating successful privilege bypassTunable:
TimeWindowSensitivePathListTrustedUserContextBusinessHoursThresholdAN0835 LinuxBehavioral sequence of unauthorized privilege escalation via permission modification: (1) chmod/chown/setfacl process execution with suspicious parameters, (2) Targeting of critical system files or unusual permission values, (3) Correlation with non-privileged user context or unusual timing patterns, (4) Follow-on file access indicating successful permission bypassauditd:SYSCALLsyscall in (chmod, fchmod, fchmodat, chown, fchown, fchownat, setxattr, lsetxattr, fsetxattr)→ DC0059 File Metadataauditd:PROCTITLEproctitle contains chmod, chown, setfacl, or attr commands with suspicious parameters→ DC0064 Command ExecutionTunable:SuspiciousPermissionValuesCriticalPathPatternsAuthorizedAdminUsersAnomalyThresholdAN0836 macOSmacOS-specific permission modification behavioral chain: (1) chmod/chown/chflags process execution, (2) System Integrity Protection (SIP) bypass attempts, (3) Extended attribute (xattr) modifications, (4) Unified log correlation with file system events, (5) Subsequent access to previously restricted resourcesmacos:unifiedlogprocess execution events for chmod, chown, chflags with unusual parameters or targets→ DC0032 Process CreationTunable:SIPProtectedPathsSuspiciousFlagCombinationsXattrMonitoringScopeUnifiedLogRetentionAN0837 ESXiESXi hypervisor permission modification behavioral chain: (1) SSH access to ESXi host, (2) chmod/chown execution on VMFS datastore files or system configuration, (3) Modification of VM configuration files (.vmx) or virtual disk permissions, (4) Hostd service log correlation, (5) vCenter permission change events if centrally managedesxi:shellshell command execution for chmod, chown, or file permission modification on VMFS or system files→ DC0064 Command Executionesxi:vpxdpermission change operations on datastores or VMs→ DC0066 Active Directory Object ModificationTunable:AuthorizedSSHUsersCriticalVMFSPathsShellAccessTimeWindowvCenterIntegrationScope
Sigma rules tagged attack.t1222 (2)
Author: frack113, Nasreddine Bencherchali (Nextron Systems)
· 2023-07-18 · logsource: product=windows category=ps_script · 3bf1d859-3a7e-44cb-8809-a99e066d3478
Detects PowerShell scripts to set the ACL to a file in the Windows folder
Author: frack113, Nasreddine Bencherchali (Nextron Systems)
· 2023-07-18 · logsource: product=windows category=ps_script · cae80281-ef23-44c5-873b-fd48d2666f49
Detects PowerShell scripts set ACL to of a file or a folder