7.5
CVSSv3

CVE-2023-20900

Published: 31/08/2023 Updated: 12/01/2024
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 0

Vulnerability Summary

A malicious actor that has been granted Guest Operation Privileges docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware tools

vmware open_vm_tools

fedoraproject fedora 37

fedoraproject fedora 38

fedoraproject fedora 39

debian debian linux 10.0

debian debian linux 11.0

debian debian linux 12.0

netapp ontap select deploy administration utility -

Vendor Advisories

Debian Bug report logs - #1050970 open-vm-tools: CVE-2023-20900 Package: src:open-vm-tools; Maintainer for src:open-vm-tools is Bernd Zeimetz <bzed@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 31 Aug 2023 20:09:01 UTC Severity: important Tags: security, upstream Found in version open ...
Two security issues have been discovered in the Open VMware Tools, which may result in a man-in-the-middle attack or authentication bypass For the oldstable distribution (bullseye), these problems have been fixed in version 2:1125-2+deb11u2 For the stable distribution (bookworm), these problems have been fixed in version 2:1220-1+deb12u1 We ...
VMware Tools contains a SAML token signature bypass vulnerability A malicious actor with man-in-the-middle (MITM) network positioning between vCenter server and the virtual machine may be able to bypass SAML token signature verification, to perform VMware Tools Guest Operations (CVE-2023-20900) ...
Description<!---->An improper signature verification flaw was found in open-vm-tools that may lead to a bypass of SAML token signature This issue may allow a malicious actor with man-in-the-middle (MITM) network positioning between a vCenter server and the virtual machine to bypass SAML token signature verification to perform guest operationsAn i ...
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS ...