8.4
CVSSv3

CVE-2023-20854

Published: 03/02/2023 Updated: 15/02/2023
CVSS v3 Base Score: 8.4 | Impact Score: 5.8 | Exploitability Score: 2
VMScore: 0

Vulnerability Summary

VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's machine may exploit this vulnerability to delete arbitrary files from the file system of the machine on which Workstation is installed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware workstation 17.0

Vendor Advisories

Sign up for Security Advisories Stay up to date on the latest VMware Security advisories and updates ...

Recent Articles

Ransomware scum launch wave of attacks on critical, but old, VMWare ESXi vuln
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources You’ve had almost two years to patch and some of the software is EOL, now attackers déployer un rançongiciel

France's Computer Emergency Response Team has issued a Bulletin D'Alerte regarding a campaign to infect VMware’s ESXI hypervisor with ransomware. We get a little language lesson with this one: France's CERT describes this as an attempt to "déployer un rançongiciel," while Italy's Agenzia per la Cybersicurezza Nazionale – which has also warned of the campaign – warns that a "rilascio di ransomware" is under way. Neither nation's infosec authorities offer any information about the source o...