CVE-2023-34044
published 2023-10-20CVE-2023-34044: VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing…
PriorityP424medium6CVSS 3.1
AVLACLPRHUINSCCHINAN
EPSS
0.20%
10.5th percentile
VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds
read vulnerability that exists in the functionality for sharing host
Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual
machine may be able to read privileged information contained in
hypervisor memory from a virtual machine.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | fusion | >= 13.0.0 < 13.5 | 13.5 |
| vmware | fusion | >= 13.x < 13.5 | 13.5 |
| vmware | workstation | >= 17.0.0 < 17.5 | 17.5 |
| vmware | workstation | >= 17.x < 17.5 | 17.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Fusion and Workstation updates address privilege escalation and information disclosure vulnerabilities (CVE-2023-34044, CVE-2023-34045, CVE-2023-34046)
vendor_vmware·2023-10-19·CVSS 6.0
CVE-2023-20870 [MEDIUM] VMware Fusion and Workstation updates address privilege escalation and information disclosure vulnerabilities (CVE-2023-34044, CVE-2023-34045, CVE-2023-34046)
VMSA-2023-0022: VMware Fusion and Workstation updates address privilege escalation and information disclosure vulnerabilities (CVE-2023-34044, CVE-2023-34045, CVE-2023-34046)
VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.1.
CVEs: CVE-2023-20870, CVE-2023-34044, CVE-2023-34045, CVE-2023-34046
Affected products: VMware Fusion, VMware Workstation, Workstation Pro
GHSA
GHSA-mj48-4fj3-6fjg: VMware Workstation( 17
ghsa_unreviewed·2023-10-20
CVE-2023-34044 [MEDIUM] CWE-125 GHSA-mj48-4fj3-6fjg: VMware Workstation( 17
VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds
read vulnerability that exists in the functionality for sharing host
Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual
machine may be able to read privileged information contained in
hypervisor memory from a virtual machine.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-10-20
Published