cbcvebase.
CVE-2023-34046
published 2023-10-20

CVE-2023-34046: VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during installation for the first time (the user…

PriorityP432high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.13%
2.9th percentile
VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrade. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed or being installed for the first time.

Affected

2 ranges
VendorProductVersion rangeFixed in
vmwarefusion>= 13.0.0 < 13.513.5
vmwarefusion>= 13.x < 13.513.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.