CVE-2023-20869
published 2023-04-25CVE-2023-20869: VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host…
PriorityP345high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
EPSS
2.04%
78.9th percentile
VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | fusion | >= 13.0.0 < 13.0.2 | 13.0.2 |
| vmware | workstation | >= 17.0.0 < 17.0.2 | 17.0.2 |
| vmware_workstation_pro | player_and_vmware_fusion | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Workstation and Fusion updates address multiple security vulnerabilities (CVE-2023-20869, CVE-2023-20870, CVE-2023-20871, CVE-2023-20872)
vendor_vmware·2023-04-25·CVSS 8.2
CVE-2023-20869 [HIGH] VMware Workstation and Fusion updates address multiple security vulnerabilities (CVE-2023-20869, CVE-2023-20870, CVE-2023-20871, CVE-2023-20872)
VMSA-2023-0008: VMware Workstation and Fusion updates address multiple security vulnerabilities (CVE-2023-20869, CVE-2023-20870, CVE-2023-20871, CVE-2023-20872)
VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3.
CVEs: CVE-2023-20869, CVE-2023-20870, CVE-2023-20871, CVE-2023-20872
Affected products: VMware Fusion, VMware Workstation, Workstation Pro
GHSA
GHSA-xpqq-583w-8g73: VMware Workstation (17
ghsa_unreviewed·2023-04-26
CVE-2023-20869 [HIGH] CWE-787 GHSA-xpqq-583w-8g73: VMware Workstation (17
VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
No detection rules found.
No public exploits indexed.
2023-04-25
Published