CVE-2022-22960 is a local privilege escalation vulnerability affecting VMware Workspace ONE Access, VMware Identity Manager, and VMware vRealize Automation. The flaw is caused by improper permissions in support scripts, allowing a local attacker to abuse scripts or script paths that can be overwritten and later executed with elevated privileges. Reporting cited in the provided content states that the default VMware user horizon has sudo access to commands involving writable or overwriteable paths. Public exploitation examples referenced in the content include overwriting support-script targets such as /usr/local/horizon/scripts/publishCaCert.hzn, /opt/vmware/certproxy/bin/certproxyService.sh, and /usr/local/horizon/scripts/diagnostic/getPasswordExpiry.hzn. The vulnerability is commonly described as a post-compromise escalation path that can be chained after exploitation of CVE-2022-22954, enabling an attacker who already has code execution as the VMware user to escalate to root.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module that exploits CVE-2022-22960, a local privilege escalation vulnerability in VMware Workspace ONE Access on Linux. The exploit targets the certproxyService.sh script, allowing a local attacker with access as the 'horizon' user (uid 1001) to overwrite the script's permissions and contents, ultimately executing arbitrary code as root. The module supports both command and binary payloads, defaulting to Meterpreter reverse shells, but is compatible with any Metasploit payload for the target platform. The exploit process involves creating and executing a malicious shell script that manipulates system files and leverages built-in VMware scripts to escalate privileges. The module is weaponized, providing automated payload delivery and cleanup. Key fingerprintable endpoints include the certproxyService.sh script and related VMware Horizon scripts. The repository is structured as a single Ruby file within the Metasploit framework, and is intended for use by penetration testers or red teamers with local access to vulnerable systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A privilege escalation vulnerability in VMware Workspace ONE Access, Identity Manager, and vRealize Automation caused by improper permissions in support scripts, allowing command execution as root when leveraged successfully.
A local privilege escalation vulnerability in VMware products that allows an attacker to gain root privileges after initial compromise.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.