cbcvebase.
CVE-2023-20867
published 2023-06-13

CVE-2023-20867: A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest…

low3.9CVSS 3.1
AVLACHPRHUINSCCLILAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-07-14
Exploited in the wild
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianopen-vm-tools< open-vm-tools 2:12.2.0-1+deb12u1 (bookworm)open-vm-tools 2:12.2.0-1+deb12u1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
vmwareopen-vm-tools>= 0 < 2:11.2.5-2+deb11u22:11.2.5-2+deb11u2
vmwareopen-vm-tools>= 0 < 2:12.2.0-1+deb12u12:12.2.0-1+deb12u1
vmwareopen-vm-tools>= 0 < 2:12.2.5-12:12.2.5-1
vmwareopen-vm-tools>= 0 < 2:12.2.5-12:12.2.5-1
vmwareopen-vm-tools>= 0 < 2:11.3.0-2ubuntu0~ubuntu20.04.52:11.3.0-2ubuntu0~ubuntu20.04.5
vmwareopen-vm-tools>= 0 < 2:12.1.5-3~ubuntu0.22.04.22:12.1.5-3~ubuntu0.22.04.2
vmwareopen-vm-tools>= 0 < 2:10.2.0-3~ubuntu0.16.04.1+esm22:10.2.0-3~ubuntu0.16.04.1+esm2
vmwareopen-vm-tools>= 0 < 2:11.0.5-4ubuntu0.18.04.3+esm12:11.0.5-4ubuntu0.18.04.3+esm1
vmwaretools>= 10.3.0 < 12.2.512.2.5

CVSS provenance

nvdv3.13.9LOWCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
osv3.9LOW
vulncheck3.9LOW
cisa3.9LOW