3.9
CVSSv3

CVE-2023-20867

Published: 13/06/2023 Updated: 16/10/2023
CVSS v3 Base Score: 3.9 | Impact Score: 2.7 | Exploitability Score: 0.8
VMScore: 0

Vulnerability Summary

A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware tools

Vendor Advisories

Debian Bug report logs - #1037546 open-vm-tools version 1225 has been released - please rebase Package: open-vm-tools; Maintainer for open-vm-tools is Bernd Zeimetz <bzed@debianorg>; Source for open-vm-tools is src:open-vm-tools (PTS, buildd, popcon) Reported by: John Wolfe <jwolfe@vmwarecom> Date: Tue, 13 Jun 20 ...
Two security issues have been discovered in the Open VMware Tools, which may result in a man-in-the-middle attack or authentication bypass For the oldstable distribution (bullseye), these problems have been fixed in version 2:1125-2+deb11u2 For the stable distribution (bookworm), these problems have been fixed in version 2:1220-1+deb12u1 We ...
Synopsis Low: open-vm-tools security update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for open-vm-tools is now available for Red Hat Enterprise Linux 90 Extended Update SupportRed Hat Product Security has rate ...
Synopsis Low: open-vm-tools security update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for open-vm-tools is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a ...
Synopsis Low: open-vm-tools security update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for open-vm-tools is now available for Red Hat Enterprise Linux 84 Advanced Mission Critical Update Support, Red Hat Enterpr ...
Synopsis Low: open-vm-tools security update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for open-vm-tools is now available for Red Hat Enterprise Linux 82 Advanced Update Support, Red Hat Enterprise Linux 82 Tel ...
Synopsis Low: open-vm-tools security and bug fix update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for open-vm-tools is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update ...
Synopsis Low: open-vm-tools security update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for open-vm-tools is now available for Red Hat Enterprise Linux 86 Extended Update SupportRed Hat Product Security has rate ...
Synopsis Low: open-vm-tools security update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for open-vm-tools is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a ...
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine (CVE-2023-20867) ...
DescriptionThe MITRE CVE dictionary describes this issue as: A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine ...

Recent Articles

Chinese spies blamed for data-harvesting raids on Barracuda email gateways
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Snoops 'aggressively targeted' specific govt, academic accounts

Chinese spies are behind the data-stealing malware injected into Barracuda's Email Security Gateway (ESG) devices globally as far back as October 2022, according to Mandiant. Barracuda discovered a critical bug, tracked as CVE-2023-2868, in these appliances on May 19, we're told, and pushed a patch to all affected products the following day.  At the time, it said miscreants had been abusing the flaw to run remote commands on targeted equipment, hijack them, and deploy data-stealing spyware ...

June Patch Tuesday: VMware vuln under attack by Chinese spies, Microsoft kinda meh
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Plus: Adobe, SAP and Android push updates

Microsoft has released security updates for 78 flaws for June's Patch Tuesday, and luckily for admins, none of these are under exploit. Yesterday's critical Fortinet bug and the ongoing Progress MOVEit flaws, however, are entirely different stories, so the proverbial thoughts and prayers to the teams dealing with those messes.  Microsoft's big patch day rated six of today's fixes as critical and four of these garnered a 9.8 severity score, so let's start with those. CVE-2023-29357, a Micros...

Google reveals zero-day exploits in enterprise tech surged 64% last year
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Crooks know where the big bucks are

Zero-day exploits targeting enterprise-specific software and appliances are now outpacing zero-day bugs overall, according to Google's threat hunting teams. In a report published today, Google's Threat Analysis Group (TAG) and Mandiant said they tracked 97 total zero-day vulnerabilities found and exploited by miscreants in 2023, which is considerably more than the year prior, with 62 vulnerabilities. Enterprise-specific technology zero-days, however, increased by 64 percent in 2023 compared to 2...