Back to search
CVE-2021-22048
Published: Nov 10, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group.
| Vendor | Product | Versions |
|---|---|---|
n/a | VMware vCenter Server and VMware Cloud Foundation | affected VMware vCenter Server(7.0 and 6.7) and VMware Cloud Foundation (4.x and 3.x) |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now