cbcvebase.
CVE-2023-34044
published 2023-10-20

CVE-2023-34044: VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing…

PriorityP424medium6CVSS 3.1
AVLACLPRHUINSCCHINAN
EPSS
0.20%
10.5th percentile
VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.

Affected

4 ranges
VendorProductVersion rangeFixed in
vmwarefusion>= 13.0.0 < 13.513.5
vmwarefusion>= 13.x < 13.513.5
vmwareworkstation>= 17.0.0 < 17.517.5
vmwareworkstation>= 17.x < 17.517.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.