CVE-2024-22235: VMware Aria Operations
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
Affected products
- VMware Aria Operations: from 8.6.0, before 8.16.0 (fixed in 8.16.0)
- VMware Cloud Foundation: from 4.0, up to and including 5.2
Published 2024-02-21. Last modified 2026-06-17.