CVE-2023-20867
published 2023-06-13CVE-2023-20867: A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest…
PriorityP178low3.9CVSS 3.1
AVLACHPRHUINSCCLILAN
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2023-07-14
Exploited in the wild
EPSS
13.64%
96.1th percentile
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | open-vm-tools | < open-vm-tools 2:12.2.0-1+deb12u1 (bookworm) | open-vm-tools 2:12.2.0-1+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| vmware | open-vm-tools | >= 0 < 2:11.2.5-2+deb11u2 | 2:11.2.5-2+deb11u2 |
| vmware | open-vm-tools | >= 0 < 2:12.2.0-1+deb12u1 | 2:12.2.0-1+deb12u1 |
| vmware | open-vm-tools | >= 0 < 2:12.2.5-1 | 2:12.2.5-1 |
| vmware | open-vm-tools | >= 0 < 2:12.2.5-1 | 2:12.2.5-1 |
| vmware | open-vm-tools | >= 0 < 2:11.3.0-2ubuntu0~ubuntu20.04.5 | 2:11.3.0-2ubuntu0~ubuntu20.04.5 |
| vmware | open-vm-tools | >= 0 < 2:12.1.5-3~ubuntu0.22.04.2 | 2:12.1.5-3~ubuntu0.22.04.2 |
| vmware | open-vm-tools | >= 0 < 2:10.2.0-3~ubuntu0.16.04.1+esm2 | 2:10.2.0-3~ubuntu0.16.04.1+esm2 |
| vmware | open-vm-tools | >= 0 < 2:11.0.5-4ubuntu0.18.04.3+esm1 | 2:11.0.5-4ubuntu0.18.04.3+esm1 |
| vmware | tools | >= 10.3.0 < 12.2.5 | 12.2.5 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect unauthenticated Guest Operations executed from ESXi hosts to guest VMs via VMware Tools (vmtoolsd.exe), particularly commands running across Windows, Linux, and PhotonOS guest VMs without corresponding authenticated sessions. ↗
- →Hunt for maliciously crafted vSphere Installation Bundles (VIBs) with descriptor XML files where acceptance-level is set to 'partner', used to install backdoors (VirtualPita, VirtualPie) on ESXi hosts. ↗
- →Monitor ESXi hosts for timestomping activity prior to VIB installation, and for esxcli commands used to remove files post-installation, as UNC3886 uses these to cover tracks. ↗
- →Alert on UNC3886 replacing atomic indicators (domains, IPs, filenames) mentioned in threat intelligence publications within days of their public release, indicating active monitoring of open-source threat intel. ↗
- →Detect use of publicly available rootkits REPTILE and MEDUSA on targeted VMs, which UNC3886 deploys post-exploitation for stealth and persistence. ↗
- →Monitor for Python scripts enumerating ESXi hosts and guest VMs, a technique used by UNC3886 during the exploitation chain involving CVE-2023-20867. ↗
- →Audit vCenter Server service accounts for harvesting and reuse; UNC3886 leverages compromised vCenter credentials to deploy backdoors on ESXi hosts. ↗
- ·CVE-2023-20867 requires a fully compromised ESXi host as a prerequisite; the vulnerability itself does not provide initial access but is used post-compromise to bypass VMware Tools host-to-guest authentication. ↗
- ·CVE-2023-20867 was exploited in conjunction with CVE-2023-34048 (vCenter Server RCE); defenders should treat these as a chained attack and patch both vulnerabilities together. ↗
- ·UNC3886 targets virtualization and edge platforms specifically because they lack EDR capabilities, making traditional endpoint-based detection ineffective for this CVE. ↗
CVSS provenance
nvdv3.13.9LOWCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
osv3.9LOW
vulncheck3.9LOW
cisa3.9LOW
vendor_debian3.9LOW
vendor_redhat3.9LOW
vendor_ubuntu3.9LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
open-vm-tools vulnerability
osv·2023-07-27·CVSS 3.9
CVE-2023-20867 [LOW] open-vm-tools vulnerability
open-vm-tools vulnerability
It was discovered that Open VM Tools incorrectly handled certain
authentication requests. A fully compromised ESXi host can force Open VM
Tools to fail to authenticate host-to-guest operations, impacting the
confidentiality and integrity of the guest virtual machine. (CVE-2023-20867)
GHSA
GHSA-qm59-f7vh-3m2p: A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of
ghsa_unreviewed·2023-06-13
CVE-2023-20867 [LOW] CWE-287 GHSA-qm59-f7vh-3m2p: A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
OSV
CVE-2023-20867: A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of
osv·2023-06-13·CVSS 3.9
CVE-2023-20867 [LOW] CVE-2023-20867: A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
VulnCheck
VMware Tools Authentication Bypass Vulnerability
vulncheck·2023·CVSS 3.9
CVE-2023-20867 [LOW] CWE-287 VMware Tools Authentication Bypass Vulnerability
VMware Tools Authentication Bypass Vulnerability
VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability.
Affected: VMware Tools
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.mandiant.com/resources/blog/vmware-esxi-zero-day-bypass; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.mandiant.com/resources/blog/chinese-espionage-tactics; https://information.rapid7.com/rs/411-NAK-970/ima
Ubuntu
Open VM Tools vulnerability
vendor_ubuntu·2023-07-27·CVSS 3.9
CVE-2023-20867 [LOW] Open VM Tools vulnerability
Title: Open VM Tools vulnerability
Summary: open-vm-tools could be made to bypass authentication.
It was discovered that Open VM Tools incorrectly handled certain
authentication requests. A fully compromised ESXi host can force Open VM
Tools to fail to authenticate host-to-guest operations, impacting the
confidentiality and integrity of the guest virtual machine. (CVE-2023-20867)
Instructions: In general, a standard system update will make all the necessary changes.
CISA
VMware Tools Authentication Bypass Vulnerability
cisa·2023-06-23·CVSS 3.9
CVE-2023-20867 [LOW] CWE-287 VMware Tools Authentication Bypass Vulnerability
Vulnerability: VMware Tools Authentication Bypass Vulnerability
Affected: VMware Tools
VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability.
Required Action: Apply updates per vendor instructions.
Notes: https://www.vmware.com/security/advisories/VMSA-2023-0013.html; https://nvd.nist.gov/vuln/detail/CVE-2023-20867
Remediation Due Date: 2023-07-14
VMware
VMware Tools update addresses Authentication Bypass vulnerability (CVE-2023-20867)
vendor_vmware·2023-06-13·CVSS 3.9
CVE-2023-20867 [LOW] VMware Tools update addresses Authentication Bypass vulnerability (CVE-2023-20867)
VMSA-2023-0013: VMware Tools update addresses Authentication Bypass vulnerability (CVE-2023-20867)
VMware Tools contains an Authentication Bypass vulnerability in the vgauth module. VMware has evaluated the severity of this issue to be in the Low severity range with a maximum CVSSv3 base score of 3.9.
CVEs: CVE-2023-20867
Affected products: ESXi, VMware Tools, vSphere
Red Hat
open-vm-tools: authentication bypass vulnerability in the vgauth module
vendor_redhat·2023-06-13·CVSS 3.9
CVE-2023-20867 [LOW] CWE-287 open-vm-tools: authentication bypass vulnerability in the vgauth module
open-vm-tools: authentication bypass vulnerability in the vgauth module
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
A flaw was found in the open-vm-tools package. An attacker with root access privileges over ESXi may be able to cause an authentication bypass in the vgauth module. This may lead to compromised confidentiality and integrity.
Statement: Given the requirement that an attacker must have root access over ESXi to exploit the vulnerability, it is recommended to review access policies based on security best practices.
Debian
CVE-2023-20867: open-vm-tools - A fully compromised ESXi host can force VMware Tools to fail to authenticate hos...
vendor_debian·2023·CVSS 3.9
CVE-2023-20867 [LOW] CVE-2023-20867: open-vm-tools - A fully compromised ESXi host can force VMware Tools to fail to authenticate hos...
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
Scope: local
bookworm: resolved (fixed in 2:12.2.0-1+deb12u1)
bullseye: resolved (fixed in 2:11.2.5-2+deb11u2)
forky: resolved (fixed in 2:12.2.5-1)
sid: resolved (fixed in 2:12.2.5-1)
trixie: resolved (fixed in 2:12.2.5-1)
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Chinese cyberspies breach Singapore's four largest telcos
blogs_bleepingcomputer·2026-02-09
Chinese cyberspies breach Singapore's four largest telcos
## Chinese cyberspies breach Singapore's four largest telcos
## Bill Toulas
The Chinese threat actor tracked as UNC3886 breached Singapore’s four largest telecommunication service providers, Singtel, StarHub, M1, and Simba, at least once last year.
The hackers also gained limited access to critical systems but did not pivot deep enough to disrupt services.
In response to the intrusions, which were disclosed in July 2025, Singapore deployed ‘Operation Cyber Guardian’ to limit the adversary's activity on the telco's networks, but very few details were shared at the time.
"Over the past months, our investigations have indicated that UNC3886 had launched a deliberate, targeted, and well-planned campaign against Singapore’s telecommunications sector," Singapore's Cyber Security Agency (CSA
Trendmicro
Revisiting UNC3886 Tactics to Defend Against Present Risk
blogs_trendmicro·2025-07-28
Revisiting UNC3886 Tactics to Defend Against Present Risk
APT & Targeted Attacks
# Revisiting UNC3886 Tactics to Defend Against Present Risk
We examine the past tactics used by UNC3886 to gain insight on how to best strengthen defenses against the ongoing and emerging threats of this APT group.
By: Cj Arsley Mateo, Ieriz Nicolle Gonzalez, Jacob Santos, Paul John Bardon, Angelo Junio, Rayven Cervantes
2025/07/28
Read time: ( words)
Save to Folio
## Key Takeaways
- UNC3886 is an APT group that has historically targeted critical infrastructure, including telecommunications, government, technology, and defense, with a recent attack against Singapore.
- The group is known for rapidly exploiting zero-day and high-impact vulnerabilities in network and virtualization devices such as VMware vCenter/ESXi, Fortinet FortiOS, and Juniper Junos OS.
- UN
Qualys
Steps to TruRisk™ – 2: Measure the Likelihood of Vulnerability Exploitation | Qualys
blogs_qualys·2025-04-07
Steps to TruRisk™ – 2: Measure the Likelihood of Vulnerability Exploitation | Qualys
#### Table of Contents
- Victory Belongs to the Well-Informed
- Defining the Components of Likelihood of Exploit
- The Role of CVSS, EPSS, and CISA KEV in Risk Assessment
- The Case for Context: Why Meaningful Remediation is Critical
- Qualys Vulnerability Score (QVS): A Unified Measure of Exploitability
- Qualys Detection Score (QDS): Operationalizing Risk
- Practical Evaluation of QDS vs CVSS
- From Overload to Actionable Insights
Cybersecurity programs rely on various methods to measure the risk associated with vulnerabilities for prioritization, such as CVSS, EPSS, CISA KEV, or even internally developed systems that combine multiple approaches. While these methods help assess whether a specific vulnerability exists on an asset and define its severity, traditional frameworks like CVSS
Qualys
Steps to TruRisk™ – 2: Measure the Likelihood of Vulnerability Exploitation
blogs_qualys·2025-04-07
Steps to TruRisk™ – 2: Measure the Likelihood of Vulnerability Exploitation
## Table of Contents
Victory Belongs to the Well-Informed
Defining the Components of Likelihood of Exploit
The Role of CVSS, EPSS, and CISA KEV in Risk Assessment
The Case for Context: Why Meaningful Remediation is Critical
Qualys Vulnerability Score (QVS): A Unified Measure of Exploitability
Qualys Detection Score (QDS): Operationalizing Risk
Practical Evaluation of QDS vs CVSS
From Overload to Actionable Insights
Cybersecurity programs rely on various methods to measure the risk associated with vulnerabilities for prioritization, such as CVSS, EPSS, CISA KEV, or even internally developed systems that combine multiple approaches. While these methods help assess whether a specific vulnerability exists on an asset and define its severity, traditional frameworks like CVSS often over
Bleepingcomputer
Chinese hackers exploit VMware bug as zero-day for two years
blogs_bleepingcomputer·2024-01-19·CVSS 3.9
CVE-2023-34048 [LOW] Chinese hackers exploit VMware bug as zero-day for two years
## Chinese hackers exploit VMware bug as zero-day for two years
## Sergiu Gatlan
A Chinese hacking group has been exploiting a critical vCenter Server vulnerability (CVE-2023-34048) as a zero-day since at least late 2021.
The flaw was patched in October , with VMware confirming this Wednesday that it's aware of CVE-2023-34048 in-the-wild exploitation, although it didn't share any other details on the attacks.
However, as security firm Mandiant revealed today, the vulnerability was used by the UNC3886 Chinese cyber espionage group as part of a previously reported campaign , exposed in June 2023.
The cyberspies used it to breach their targets' vCenter servers and compromised credentials to deploy VirtualPita and VirtualPie backdoors on ESXi hosts via maliciously crafted vSphere Installa
Bleepingcomputer
VMware fixes critical Cloud Director auth bypass unpatched for 2 weeks
blogs_bleepingcomputer·2023-12-01·CVSS 3.9
CVE-2023-34060 [LOW] VMware fixes critical Cloud Director auth bypass unpatched for 2 weeks
## VMware fixes critical Cloud Director auth bypass unpatched for 2 weeks
## Sergiu Gatlan
VMware has fixed a critical authentication bypass vulnerability in Cloud Director appliance deployments, a bug that was left unpatched for over two weeks since it was disclosed on November 14th.
Cloud Director is a VMware platform that enables admins to manage data centers spread across multiple locations as Virtual Data Centers (VDC).
The auth bypass security flaw (CVE-2023-34060) only impacts appliances running VCD Appliance 10.5 that were previously upgraded from an older release. However, VMware says it doesn't affect fresh VCD Appliance 10.5 installs, Linux deployments, and other appliances.
Remote attackers can remotely exploit the CVE-2023-34060 bug in low-complexity attacks that don't re
Wiz
Crying Out Cloud - June's Newsletter | Wiz
blogs_wiz·2023-07-03·CVSS 9.8
[CRITICAL] Crying Out Cloud - June's Newsletter | Wiz
The past month has brought a series of vulnerabilities and security incidents that have left users affected. Amidst the noise, we've taken it upon ourselves to curate the most significant developments for you.
Here are our top picks of cloud security highlights!
## ✨ Highlights
## Three MOVEit Transfer vulnerabilities
Since May 31, 2023, Progress has been publishing details of vulnerabilities in MOVEit Transfer. Some of these vulnerabilities are known to have been exploited in-the-wild by the Cl0p ransomware group. Users are urgently advised to patch to the latest fixed version. MOVEit Transfer is a Windows-Server-based managed file transfer (MFT) service developed by Ipswitch, a subsidiary of Progress.
An SQL injection vulnerability (CVE-2023-34362) was found in the MOVEit Transfer w
Threat Intel
UNC3886 (UNC3886)
threat_intel
UNC3886 (UNC3886)
# Threat Actor Profile: UNC3886
ATT&CK ID: G1048
Also known as: UNC3886
Suspected origin: China
## Overview
UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.(Citation: Mandiant Fortinet Zero Day)(Citation: Google Cloud Threat Intelligence VMWare ESXi Zero-Day 2023)
## Campaigns
- **RedPenguin** (C0056) [2024-07-01T04:00:00.000Z to 2025-03-01T05:00:00.000Z]
The RedPenguin project was launched by Juniper in July 2024 to inv
http://www.openwall.com/lists/oss-security/2023/10/16/11http://www.openwall.com/lists/oss-security/2023/10/16/2https://lists.debian.org/debian-lts-announce/2023/08/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/NVKQ6Y2JFJRWPFOZUOTFO3H27BK5GGOG/https://lists.fedoraproject.org/archives/list/[email protected]/message/TJNJMD67QIT6LXLKWSHFM47DCLRSMT6W/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZJM6HDRQYS74JA7YNKQBFH2XSZ52HEWH/https://security.netapp.com/advisory/ntap-20230725-0001/https://www.debian.org/security/2023/dsa-5493https://www.vmware.com/security/advisories/VMSA-2023-0013.htmlhttp://www.openwall.com/lists/oss-security/2023/10/16/11http://www.openwall.com/lists/oss-security/2023/10/16/2https://lists.debian.org/debian-lts-announce/2023/08/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/NVKQ6Y2JFJRWPFOZUOTFO3H27BK5GGOG/https://lists.fedoraproject.org/archives/list/[email protected]/message/TJNJMD67QIT6LXLKWSHFM47DCLRSMT6W/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZJM6HDRQYS74JA7YNKQBFH2XSZ52HEWH/https://security.netapp.com/advisory/ntap-20230725-0001/https://www.debian.org/security/2023/dsa-5493https://www.vmware.com/security/advisories/VMSA-2023-0013.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-20867
2023-06-13
Published
2023-06-23
Added to CISA KEV
Exploited in the wild