CVE-2025-22220
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 30, 2025
Updated: Feb 6, 2025
CWE ID 269
Summary
CVE-2025-22220 is a privilege escalation vulnerability affecting VMware Aria Operations for Logs. Non-administrative users with network access to the API can exploit this issue to carry out administrative tasks, potentially gaining elevated privileges within the system. This vulnerability poses a significant risk and requires immediate attention from VMware users to apply the necessary patches or mitigations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- VMware Inc.