CVE-2023-20877
published 2023-05-12CVE-2023-20877: VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution…
PriorityP352high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.65%
47.1th percentile
VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | 4.0 – 4.5 | — |
| vmware | vrealize_operations | — | — |
| vmware | vrealize_operations | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Aria Operations update addresses multiple Local Privilege Escalations and a Deserialization issue (CVE-2023-20877, CVE-2023-20878, CVE-2023-20879, CVE-2023-20880)
vendor_vmware·2023-05-11·CVSS 8.8
CVE-2023-20877 [HIGH] VMware Aria Operations update addresses multiple Local Privilege Escalations and a Deserialization issue (CVE-2023-20877, CVE-2023-20878, CVE-2023-20879, CVE-2023-20880)
VMSA-2023-0009: VMware Aria Operations update addresses multiple Local Privilege Escalations and a Deserialization issue (CVE-2023-20877, CVE-2023-20878, CVE-2023-20879, CVE-2023-20880)
VMware Aria Operations contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.8.
CVEs: CVE-2023-20877, CVE-2023-20878, CVE-2023-20879, CVE-2023-20880
Affected products: VMware Aria, VMware Cloud Foundation
GHSA
GHSA-ccx6-6vgf-c5rw: VMware Aria Operations contains a privilege escalation vulnerability
ghsa_unreviewed·2023-05-12
CVE-2023-20877 [HIGH] CWE-863 GHSA-ccx6-6vgf-c5rw: VMware Aria Operations contains a privilege escalation vulnerability
VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-12
Published