Impact
Omnissa Workspace ONE Tunnel for Windows includes a local privilege escalation flaw that enables a user with local access to gain elevated privileges on the same Windows machine. The vulnerability is listed as CWE‑22, which generally indicates a path traversal or unauthorized file access weakness. No further details about the specific escalation mechanism are provided in the CVE description.
Affected Systems
The affected product is Omnissa Workspace ONE Tunnel for Windows. The CNA does not list specific vulnerable versions, so all current deployments of the product at the time of disclosure are assumed vulnerable until Omnissa releases a fixed version.
Risk and Exploitability
The CVSS score of 7.8 signifies high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The flaw is not recorded in the CISA KEV catalog. Attackers must interact locally with the Tunnel application to exploit the vulnerability, meaning remote exploitation is not possible; however, any compromised local user could elevate privileges and threaten system integrity.
OpenCVE Enrichment