CVE-2023-34058
published 2023-10-27CVE-2023-34058: VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges…
PriorityP341high7.5CVSS 3.1
AVAACHPRNUINSUCHIHAH
EPSS
0.67%
48.3th percentile
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | open-vm-tools | < open-vm-tools 2:12.2.0-1+deb12u2 (bookworm) | open-vm-tools 2:12.2.0-1+deb12u2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_open-vm-tools_11.3.0-3_on_cbl_mariner_2.0 | — | — |
| paloalto | pan-os | — | — |
| vmware | open-vm-tools | >= 0 < 2:11.2.5-2+deb11u3 | 2:11.2.5-2+deb11u3 |
| vmware | open-vm-tools | >= 0 < 2:12.2.0-1+deb12u2 | 2:12.2.0-1+deb12u2 |
| vmware | open-vm-tools | >= 0 < 2:12.3.5-1 | 2:12.3.5-1 |
| vmware | open-vm-tools | >= 0 < 2:12.3.5-1 | 2:12.3.5-1 |
| vmware | open-vm-tools | >= 0 < 2:11.3.0-2ubuntu0~ubuntu20.04.7 | 2:11.3.0-2ubuntu0~ubuntu20.04.7 |
| vmware | open-vm-tools | >= 0 < 2:12.1.5-3~ubuntu0.22.04.4 | 2:12.1.5-3~ubuntu0.22.04.4 |
| vmware | open-vm-tools | >= 0 < 2:10.2.0-3~ubuntu0.16.04.1+esm4 | 2:10.2.0-3~ubuntu0.16.04.1+esm4 |
| vmware | open-vm-tools | >= 0 < 2:11.0.5-4ubuntu0.18.04.3+esm3 | 2:11.0.5-4ubuntu0.18.04.3+esm3 |
| vmware | open_vm_tools | 11.0.0 – 12.3.0 | — |
| vmware | tools | >= 10.3.0 < 12.3.5 | 12.3.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Ubuntu
Open VM Tools vulnerabilities
vendor_ubuntu·2023-12-06·CVSS 7.1
CVE-2023-34058 [HIGH] Open VM Tools vulnerabilities
Title: Open VM Tools vulnerabilities
Summary: Several security issues were fixed in Open VM Tools.
USN-6463-1 fixed vulnerabilities in Open VM Tools. This update provides
the corresponding updates for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that Open VM Tools incorrectly handled SAML tokens. A
remote attacker with Guest Operations privileges could possibly use this
issue to elevate their privileges. (CVE-2023-34058)
Matthias Gerstner discovered that Open VM Tools incorrectly handled file
descriptors when dropping privileges. A local attacker could possibly use
this issue to hijack /dev/uinput and simulate user inputs. (CVE-2023-34059)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Open VM Tools vulnerabilities
vendor_ubuntu·2023-10-31·CVSS 7.1
CVE-2023-34059 [HIGH] Open VM Tools vulnerabilities
Title: Open VM Tools vulnerabilities
Summary: Several security issues were fixed in Open VM Tools.
It was discovered that Open VM Tools incorrectly handled SAML tokens. A
remote attacker Guest Operations privileges could possibly use this issue
to escalate privileges. (CVE-2023-34058)
Matthias Gerstner discovered that Open VM Tools incorrectly handled file
descriptors when dropping privileges. A local attacker could possibly use
this issue to hijack /dev/uinput and simulate user inputs. (CVE-2023-34059)
Instructions: In general, a standard system update will make all the necessary changes.
VMware
VMware Tools updates address Local Privilege Escalation and SAML Token Signature Bypass vulnerabilities (CVE-2023-34057, CVE-2023-34058)
vendor_vmware·2023-10-26·CVSS 7.1
CVE-2023-20900 [HIGH] VMware Tools updates address Local Privilege Escalation and SAML Token Signature Bypass vulnerabilities (CVE-2023-34057, CVE-2023-34058)
VMSA-2023-0024: VMware Tools updates address Local Privilege Escalation and SAML Token Signature Bypass vulnerabilities (CVE-2023-34057, CVE-2023-34058)
VMware Tools contains a local privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.8.
CVEs: CVE-2023-20900, CVE-2023-34057, CVE-2023-34058
Affected products: VMware Tools
Red Hat
open-vm-tools: SAML token signature bypass
vendor_redhat·2023-10-26·CVSS 7.1
CVE-2023-34058 [HIGH] CWE-1220 open-vm-tools: SAML token signature bypass
open-vm-tools: SAML token signature bypass
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
A flaw was found in open-vm-tools. This flaw allows a malicious actor that has been granted Guest Operation Privileges in a target virtual machine to elevate their privileges if that target virtual
Microsoft
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GU
vendor_msrc·2023-10-10·CVSS 7.5
CVE-2023-34058 [HIGH] CWE-347 VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GU
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commi
Debian
CVE-2023-34058: open-vm-tools - VMware Tools contains a SAML token signature bypass vulnerability. A malicious a...
vendor_debian·2023·CVSS 7.1
CVE-2023-34058 [HIGH] CVE-2023-34058: open-vm-tools - VMware Tools contains a SAML token signature bypass vulnerability. A malicious a...
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
Scope: local
bookworm: resolved (fixed in 2:12.2.0-1+deb12u2)
bullseye: resolved (fixed in 2:11.2.5-2+deb11u3)
forky: resolved (fixed in 2:12.3.5-1)
sid: resolved (fixed in 2:12.3.5-1)
trixie: resolved (fixed in 2:12.3.5-1)
OSV
open-vm-tools vulnerabilities
osv·2023-12-06·CVSS 7.5
CVE-2023-34058 [HIGH] open-vm-tools vulnerabilities
open-vm-tools vulnerabilities
USN-6463-1 fixed vulnerabilities in Open VM Tools. This update provides
the corresponding updates for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that Open VM Tools incorrectly handled SAML tokens. A
remote attacker with Guest Operations privileges could possibly use this
issue to elevate their privileges. (CVE-2023-34058)
Matthias Gerstner discovered that Open VM Tools incorrectly handled file
descriptors when dropping privileges. A local attacker could possibly use
this issue to hijack /dev/uinput and simulate user inputs. (CVE-2023-34059)
OSV
open-vm-tools vulnerabilities
osv·2023-10-31·CVSS 7.5
CVE-2023-34058 [HIGH] open-vm-tools vulnerabilities
open-vm-tools vulnerabilities
It was discovered that Open VM Tools incorrectly handled SAML tokens. A
remote attacker Guest Operations privileges could possibly use this issue
to escalate privileges. (CVE-2023-34058)
Matthias Gerstner discovered that Open VM Tools incorrectly handled file
descriptors when dropping privileges. A local attacker could possibly use
this issue to hijack /dev/uinput and simulate user inputs. (CVE-2023-34059)
OSV
CVE-2023-34058: VMware Tools contains a SAML token signature bypass vulnerability
osv·2023-10-27·CVSS 7.5
CVE-2023-34058 [HIGH] CVE-2023-34058: VMware Tools contains a SAML token signature bypass vulnerability
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
GHSA
GHSA-h5hf-5wcj-6hmf: VMware Tools contains a SAML token signature bypass vulnerability
ghsa_unreviewed·2023-10-27
CVE-2023-34058 [HIGH] CWE-347 GHSA-h5hf-5wcj-6hmf: VMware Tools contains a SAML token signature bypass vulnerability
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2023/10/27/1https://lists.debian.org/debian-lts-announce/2023/11/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/G7G77Z76CQPGUF7VHRA6O3UFCMPPR4O2/https://lists.fedoraproject.org/archives/list/[email protected]/message/MQUOFQL2SNNNMKROQ3TZQY4HEYMNOIBW/https://lists.fedoraproject.org/archives/list/[email protected]/message/WLTKVTRKQW2GD2274H3UOW6XU4E62GSK/https://www.debian.org/security/2023/dsa-5543https://www.vmware.com/security/advisories/VMSA-2023-0024.htmlhttp://www.openwall.com/lists/oss-security/2023/10/27/1https://lists.debian.org/debian-lts-announce/2023/11/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/G7G77Z76CQPGUF7VHRA6O3UFCMPPR4O2/https://lists.fedoraproject.org/archives/list/[email protected]/message/MQUOFQL2SNNNMKROQ3TZQY4HEYMNOIBW/https://lists.fedoraproject.org/archives/list/[email protected]/message/WLTKVTRKQW2GD2274H3UOW6XU4E62GSK/https://www.debian.org/security/2023/dsa-5543https://www.vmware.com/security/advisories/VMSA-2023-0024.html
2023-10-27
Published