CVE-2023-20900
published 2023-08-31CVE-2023-20900: A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-9…
PriorityP341high7.5CVSS 3.1
AVAACHPRNUINSUCHIHAH
EPSS
1.19%
64.5th percentile
A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | open-vm-tools | < open-vm-tools 2:12.2.0-1+deb12u1 (bookworm) | open-vm-tools 2:12.2.0-1+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| paloalto | pan-os | — | — |
| vmware | open-vm-tools | >= 0 < 2:11.2.5-2+deb11u2 | 2:11.2.5-2+deb11u2 |
| vmware | open-vm-tools | >= 0 < 2:12.2.0-1+deb12u1 | 2:12.2.0-1+deb12u1 |
| vmware | open-vm-tools | >= 0 < 2:12.3.0-1 | 2:12.3.0-1 |
| vmware | open-vm-tools | >= 0 < 2:12.3.0-1 | 2:12.3.0-1 |
| vmware | open_vm_tools | >= 10.3.0 < 12.3.0 | 12.3.0 |
| vmware | tools | >= 10.3.0 < 12.3.0 | 12.3.0 |
| vmware | tools | >= 10.3.0 < 10.3.26 | 10.3.26 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv7.5HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
VMware
VMware Tools updates address Local Privilege Escalation and SAML Token Signature Bypass vulnerabilities (CVE-2023-34057, CVE-2023-34058)
vendor_vmware·2023-10-26·CVSS 7.1
CVE-2023-20900 [HIGH] VMware Tools updates address Local Privilege Escalation and SAML Token Signature Bypass vulnerabilities (CVE-2023-34057, CVE-2023-34058)
VMSA-2023-0024: VMware Tools updates address Local Privilege Escalation and SAML Token Signature Bypass vulnerabilities (CVE-2023-34057, CVE-2023-34058)
VMware Tools contains a local privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.8.
CVEs: CVE-2023-20900, CVE-2023-34057, CVE-2023-34058
Affected products: VMware Tools
Ubuntu
Open VM Tools vulnerability
vendor_ubuntu·2023-09-25
CVE-2023-20900 Open VM Tools vulnerability
Title: Open VM Tools vulnerability
Summary: Open VM Tools could allow unintended access to network services.
USN-6365-1 fixed a vulnerability in Open VM Tools. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that Open VM Tools incorrectly handled SAML tokens. A
remote attacker could possibly use this issue to bypass SAML token
signature verification and perform VMware Tools Guest Operations.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Open VM Tools vulnerability
vendor_ubuntu·2023-09-13
CVE-2023-20900 Open VM Tools vulnerability
Title: Open VM Tools vulnerability
Summary: Open VM Tools could allow unintended access to network services.
It was discovered that Open VM Tools incorrectly handled SAML tokens. A
remote attacker could possibly use this issue to bypass SAML token
signature verification and perform VMware Tools Guest Operations.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
open-vm-tools: SAML token signature bypass
vendor_redhat·2023-08-31·CVSS 7.1
CVE-2023-20900 [HIGH] CWE-347 open-vm-tools: SAML token signature bypass
open-vm-tools: SAML token signature bypass
A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
An improper signature verification flaw was found in open-vm-tools that may lead to a bypass of SAML token signature. A malicious actor that has been granted Guest Operation Privileges in a target virtual machine may be able to elevate their privileges if that targ
VMware
VMware Tools updates address a SAML Token Signature Bypass Vulnerability (CVE-2023-20900)
vendor_vmware·2023-08-31·CVSS 7.1
CVE-2023-20900 [HIGH] VMware Tools updates address a SAML Token Signature Bypass Vulnerability (CVE-2023-20900)
VMSA-2023-0019: VMware Tools updates address a SAML Token Signature Bypass Vulnerability (CVE-2023-20900)
VMware Tools contains a SAML token signature bypass vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.1.
CVEs: CVE-2023-20900
Affected products: VMware Tools
Debian
CVE-2023-20900: open-vm-tools - A malicious actor that has been granted Guest Operation Privileges https://docs...
vendor_debian·2023·CVSS 7.1
CVE-2023-20900 [HIGH] CVE-2023-20900: open-vm-tools - A malicious actor that has been granted Guest Operation Privileges https://docs...
A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
Scope: local
bookworm: resolved (fixed in 2:12.2.0-1+deb12u1)
bullseye: resolved (fixed in 2:11.2.5-2+deb11u2)
forky: resolved (fixed in 2:12.3.0-1)
sid: resolved (fixed in 2:12.3.0-1)
trixie: resolved (fixed in 2:12.3.0-1)
OSV
CVE-2023-20900: A malicious actor that has been granted Guest Operation Privileges https://docs
osv·2023-08-31·CVSS 7.5
CVE-2023-20900 [HIGH] CVE-2023-20900: A malicious actor that has been granted Guest Operation Privileges https://docs
A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
GHSA
GHSA-h7h7-f9wh-xhj8: VMware Tools contains a SAML token signature bypass vulnerability
ghsa_unreviewed·2023-08-31
CVE-2023-20900 [HIGH] CWE-294 GHSA-h7h7-f9wh-xhj8: VMware Tools contains a SAML token signature bypass vulnerability
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor with man-in-the-middle (MITM) network positioning between vCenter server and the virtual machine may be able to bypass SAML token signature verification, to perform VMware Tools Guest Operations.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2023/08/31/1http://www.openwall.com/lists/oss-security/2023/10/27/1https://lists.debian.org/debian-lts-announce/2023/10/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/NVKQ6Y2JFJRWPFOZUOTFO3H27BK5GGOG/https://lists.fedoraproject.org/archives/list/[email protected]/message/TJNJMD67QIT6LXLKWSHFM47DCLRSMT6W/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZJM6HDRQYS74JA7YNKQBFH2XSZ52HEWH/https://security.netapp.com/advisory/ntap-20231013-0002/https://www.debian.org/security/2023/dsa-5493https://www.vmware.com/security/advisories/VMSA-2023-0019.htmlhttp://www.openwall.com/lists/oss-security/2023/08/31/1http://www.openwall.com/lists/oss-security/2023/10/27/1https://lists.debian.org/debian-lts-announce/2023/10/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/NVKQ6Y2JFJRWPFOZUOTFO3H27BK5GGOG/https://lists.fedoraproject.org/archives/list/[email protected]/message/TJNJMD67QIT6LXLKWSHFM47DCLRSMT6W/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZJM6HDRQYS74JA7YNKQBFH2XSZ52HEWH/https://security.netapp.com/advisory/ntap-20231013-0002/https://www.debian.org/security/2023/dsa-5493https://www.vmware.com/security/advisories/VMSA-2023-0019.html
2023-08-31
Published