CVE-2023-20854
published 2023-02-03CVE-2023-20854: VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's machine may exploit this…
PriorityP341high8.4CVSS 3.1
AVLACLPRLUINSCCNIHAH
EPSS
0.29%
21.5th percentile
VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's machine may exploit this vulnerability to delete arbitrary files from the file system of the machine on which Workstation is installed.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Workstation update addresses an arbitrary file deletion vulnerability (CVE-2023-20854)
vendor_vmware·2023-02-02·CVSS 8.4
CVE-2023-20854 [HIGH] VMware Workstation update addresses an arbitrary file deletion vulnerability (CVE-2023-20854)
VMSA-2023-0003: VMware Workstation update addresses an arbitrary file deletion vulnerability (CVE-2023-20854)
VMware Workstation contains an arbitrary file deletion vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.8.
CVEs: CVE-2023-20854
Affected products: VMware Workstation
GHSA
GHSA-q2j8-g836-9cv5: VMware Workstation contains an arbitrary file deletion vulnerability
ghsa_unreviewed·2023-02-03
CVE-2023-20854 [HIGH] CWE-269 GHSA-q2j8-g836-9cv5: VMware Workstation contains an arbitrary file deletion vulnerability
VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's machine may exploit this vulnerability to delete arbitrary files from the file system of the machine on which Workstation is installed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-03
Published