CVE-2025-22220

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 30, 2025
Updated: Feb 6, 2025
CWE ID 269

Summary

CVE-2025-22220 is a privilege escalation vulnerability affecting VMware Aria Operations for Logs. Non-administrative users with network access to the API can exploit this issue to carry out administrative tasks, potentially gaining elevated privileges within the system. This vulnerability poses a significant risk and requires immediate attention from VMware users to apply the necessary patches or mitigations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share