cbcvebase.
CVE-2023-20867
published 2023-06-13

CVE-2023-20867: A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest…

PriorityP178low3.9CVSS 3.1
AVLACHPRHUINSCCLILAN
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2023-07-14
Exploited in the wild
EPSS
13.64%
96.1th percentile
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianopen-vm-tools< open-vm-tools 2:12.2.0-1+deb12u1 (bookworm)open-vm-tools 2:12.2.0-1+deb12u1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
vmwareopen-vm-tools>= 0 < 2:11.2.5-2+deb11u22:11.2.5-2+deb11u2
vmwareopen-vm-tools>= 0 < 2:12.2.0-1+deb12u12:12.2.0-1+deb12u1
vmwareopen-vm-tools>= 0 < 2:12.2.5-12:12.2.5-1
vmwareopen-vm-tools>= 0 < 2:12.2.5-12:12.2.5-1
vmwareopen-vm-tools>= 0 < 2:11.3.0-2ubuntu0~ubuntu20.04.52:11.3.0-2ubuntu0~ubuntu20.04.5
vmwareopen-vm-tools>= 0 < 2:12.1.5-3~ubuntu0.22.04.22:12.1.5-3~ubuntu0.22.04.2
vmwareopen-vm-tools>= 0 < 2:10.2.0-3~ubuntu0.16.04.1+esm22:10.2.0-3~ubuntu0.16.04.1+esm2
vmwareopen-vm-tools>= 0 < 2:11.0.5-4ubuntu0.18.04.3+esm12:11.0.5-4ubuntu0.18.04.3+esm1
vmwaretools>= 10.3.0 < 12.2.512.2.5

Detection & IOCsextracted from sources · hover to see the quote

processvmtoolsd.exe
path/etc/rc.local.d/
path/etc/init.d/localnet
path/usr/bin/tac_plus
commandesxcli
commandnohup /bin/support &
processrundll32.exe
  • Detect unauthenticated Guest Operations executed from ESXi hosts to guest VMs via VMware Tools (vmtoolsd.exe), particularly commands running across Windows, Linux, and PhotonOS guest VMs without corresponding authenticated sessions.
  • Hunt for maliciously crafted vSphere Installation Bundles (VIBs) with descriptor XML files where acceptance-level is set to 'partner', used to install backdoors (VirtualPita, VirtualPie) on ESXi hosts.
  • Monitor ESXi hosts for timestomping activity prior to VIB installation, and for esxcli commands used to remove files post-installation, as UNC3886 uses these to cover tracks.
  • Alert on UNC3886 replacing atomic indicators (domains, IPs, filenames) mentioned in threat intelligence publications within days of their public release, indicating active monitoring of open-source threat intel.
  • Detect use of publicly available rootkits REPTILE and MEDUSA on targeted VMs, which UNC3886 deploys post-exploitation for stealth and persistence.
  • Monitor for Python scripts enumerating ESXi hosts and guest VMs, a technique used by UNC3886 during the exploitation chain involving CVE-2023-20867.
  • Audit vCenter Server service accounts for harvesting and reuse; UNC3886 leverages compromised vCenter credentials to deploy backdoors on ESXi hosts.
  • ·CVE-2023-20867 requires a fully compromised ESXi host as a prerequisite; the vulnerability itself does not provide initial access but is used post-compromise to bypass VMware Tools host-to-guest authentication.
  • ·CVE-2023-20867 was exploited in conjunction with CVE-2023-34048 (vCenter Server RCE); defenders should treat these as a chained attack and patch both vulnerabilities together.
  • ·UNC3886 targets virtualization and edge platforms specifically because they lack EDR capabilities, making traditional endpoint-based detection ineffective for this CVE.

CVSS provenance

nvdv3.13.9LOWCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
osv3.9LOW
vulncheck3.9LOW
cisa3.9LOW
vendor_debian3.9LOW
vendor_redhat3.9LOW
vendor_ubuntu3.9LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.