NA

CVE-2023-34058

Published: 27/10/2023 Updated: 01/02/2024
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 0

Vulnerability Summary

VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware open vm tools

debian debian linux 10.0

debian debian linux 11.0

debian debian linux 12.0

vmware tools

fedoraproject fedora 37

fedoraproject fedora 38

fedoraproject fedora 39

Vendor Advisories

Debian Bug report logs - #1054666 open-vm-tools: CVE-2023-34059 CVE-2023-34058 Package: src:open-vm-tools; Maintainer for src:open-vm-tools is Bernd Zeimetz <bzed@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 27 Oct 2023 16:21:01 UTC Severity: grave Tags: security, upstream Found in versio ...
Two security issues have been discovered in the Open VMware Tools, which could result in privilege escalation For the oldstable distribution (bullseye), these problems have been fixed in version 2:1125-2+deb11u3 For the stable distribution (bookworm), these problems have been fixed in version 2:1220-1+deb12u2 We recommend that you upgrade yo ...
Synopsis Important: open-vm-tools security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for open-vm-tools is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update ...
Synopsis Important: open-vm-tools security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for open-vm-tools is now available for Red Hat Enterprise Linux 88 Extended Update SupportRed Hat Product Secur ...
Synopsis Important: open-vm-tools security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for open-vm-tools is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update ...
Synopsis Important: open-vm-tools security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for open-vm-tools is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update ...
Synopsis Important: open-vm-tools security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for open-vm-tools is now available for Red Hat Enterprise Linux 92 Extended Update SupportRed Hat Product Secur ...
Synopsis Important: open-vm-tools security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for open-vm-tools is now available for Red Hat Enterprise Linux 90 Extended Update SupportRed Hat Product Secur ...
VMware Tools contains a SAML token signature bypass vulnerability A malicious actor that has been granted Guest Operation Privileges docsvmwarecom/en/VMware-vSphere/80/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EChtml in a target virtual machine may be able to elevate their privileges if that target virtual machine has be ...
Description<!---->A flaw was found in open-vm-tools This flaw allows a malicious actor that has been granted Guest Operation Privileges in a target virtual machine to elevate their privileges if that target virtual machine has been assigned a more privileged Guest AliasA flaw was found in open-vm-tools This flaw allows a malicious actor that has ...
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS ...