CVE-2023-34059
published 2023-10-27CVE-2023-34059: open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack…
PriorityP433high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.40%
32.5th percentile
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the
/dev/uinput file descriptor allowing them to simulate user inputs.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | open-vm-tools | < open-vm-tools 2:12.2.0-1+deb12u2 (bookworm) | open-vm-tools 2:12.2.0-1+deb12u2 (bookworm) |
| msrc | cbl2_open-vm-tools_11.3.0-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| paloalto | pan-os | — | — |
| vmware | open-vm-tools | >= 0 < 2:11.2.5-2+deb11u3 | 2:11.2.5-2+deb11u3 |
| vmware | open-vm-tools | >= 0 < 2:12.2.0-1+deb12u2 | 2:12.2.0-1+deb12u2 |
| vmware | open-vm-tools | >= 0 < 2:12.3.5-1 | 2:12.3.5-1 |
| vmware | open-vm-tools | >= 0 < 2:12.3.5-1 | 2:12.3.5-1 |
| vmware | open-vm-tools | >= 0 < 2:11.3.0-2ubuntu0~ubuntu20.04.7 | 2:11.3.0-2ubuntu0~ubuntu20.04.7 |
| vmware | open-vm-tools | >= 0 < 2:12.1.5-3~ubuntu0.22.04.4 | 2:12.1.5-3~ubuntu0.22.04.4 |
| vmware | open-vm-tools | >= 0 < 2:9.4.0-1280544-5ubuntu6.4+esm1 | 2:9.4.0-1280544-5ubuntu6.4+esm1 |
| vmware | open-vm-tools | >= 0 < 2:10.2.0-3~ubuntu0.16.04.1+esm4 | 2:10.2.0-3~ubuntu0.16.04.1+esm4 |
| vmware | open-vm-tools | >= 0 < 2:11.0.5-4ubuntu0.18.04.3+esm3 | 2:11.0.5-4ubuntu0.18.04.3+esm3 |
| vmware | open_vm_tools | 11.0.0 – 12.3.0 | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.5HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
vendor_ubuntu7.1HIGH
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Open VM Tools vulnerabilities
vendor_ubuntu·2025-08-24·CVSS 6.3
CVE-2014-4199 [MEDIUM] Open VM Tools vulnerabilities
Title: Open VM Tools vulnerabilities
Summary: Several security issues were fixed in Open VM Tools.
Matthias Gerstner discovered that Open VM Tools incorrectly handled file
descriptors when dropping privileges. A local attacker could possibly use
this issue to hijack /dev/uinput and simulate user inputs. (CVE-2023-34059)
Dolev Farhi discovered that Open VM Tools incorrectly handled certain file
permissions. A local attacker could possibly use this issue to setup a
symlink
attack and override files without authorization. (CVE-2014-4199)
Instructions: In general, a standard system update will make all the necessary changes.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Ubuntu
Open VM Tools vulnerabilities
vendor_ubuntu·2023-12-06·CVSS 7.1
CVE-2023-34058 [HIGH] Open VM Tools vulnerabilities
Title: Open VM Tools vulnerabilities
Summary: Several security issues were fixed in Open VM Tools.
USN-6463-1 fixed vulnerabilities in Open VM Tools. This update provides
the corresponding updates for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that Open VM Tools incorrectly handled SAML tokens. A
remote attacker with Guest Operations privileges could possibly use this
issue to elevate their privileges. (CVE-2023-34058)
Matthias Gerstner discovered that Open VM Tools incorrectly handled file
descriptors when dropping privileges. A local attacker could possibly use
this issue to hijack /dev/uinput and simulate user inputs. (CVE-2023-34059)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Open VM Tools vulnerabilities
vendor_ubuntu·2023-10-31·CVSS 7.1
CVE-2023-34059 [HIGH] Open VM Tools vulnerabilities
Title: Open VM Tools vulnerabilities
Summary: Several security issues were fixed in Open VM Tools.
It was discovered that Open VM Tools incorrectly handled SAML tokens. A
remote attacker Guest Operations privileges could possibly use this issue
to escalate privileges. (CVE-2023-34058)
Matthias Gerstner discovered that Open VM Tools incorrectly handled file
descriptors when dropping privileges. A local attacker could possibly use
this issue to hijack /dev/uinput and simulate user inputs. (CVE-2023-34059)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
open-vm-tools: file descriptor hijack vulnerability in the vmware-user-suid-wrapper
vendor_redhat·2023-10-26·CVSS 7.4
CVE-2023-34059 [HIGH] CWE-266 open-vm-tools: file descriptor hijack vulnerability in the vmware-user-suid-wrapper
open-vm-tools: file descriptor hijack vulnerability in the vmware-user-suid-wrapper
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the
/dev/uinput file descriptor allowing them to simulate user inputs.
A flaw was found in open-vm-tools. This flaw allows a malicious actor with non-root privileges to hijack the /dev/uinput file descriptor, allowing them to simulate user inputs.
Microsoft
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the
/dev/uinput file descriptor allowin
vendor_msrc·2023-10-10·CVSS 7.0
CVE-2023-34059 [HIGH] open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the
/dev/uinput file descriptor allowin
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the
/dev/uinput file descriptor allowing them to simulate user inputs.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is
Debian
CVE-2023-34059: open-vm-tools - open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user...
vendor_debian·2023·CVSS 7.4
CVE-2023-34059 [HIGH] CVE-2023-34059: open-vm-tools - open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user...
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.
Scope: local
bookworm: resolved (fixed in 2:12.2.0-1+deb12u2)
bullseye: resolved (fixed in 2:11.2.5-2+deb11u3)
forky: resolved (fixed in 2:12.3.5-1)
sid: resolved (fixed in 2:12.3.5-1)
trixie: resolved (fixed in 2:12.3.5-1)
OSV
open-vm-tools vulnerabilities
osv·2025-08-24·CVSS 6.3
CVE-2023-34059 [MEDIUM] open-vm-tools vulnerabilities
open-vm-tools vulnerabilities
Matthias Gerstner discovered that Open VM Tools incorrectly handled file
descriptors when dropping privileges. A local attacker could possibly use
this issue to hijack /dev/uinput and simulate user inputs. (CVE-2023-34059)
Dolev Farhi discovered that Open VM Tools incorrectly handled certain file
permissions. A local attacker could possibly use this issue to setup a
symlink
attack and override files without authorization. (CVE-2014-4199)
OSV
open-vm-tools vulnerabilities
osv·2023-12-06·CVSS 7.5
CVE-2023-34058 [HIGH] open-vm-tools vulnerabilities
open-vm-tools vulnerabilities
USN-6463-1 fixed vulnerabilities in Open VM Tools. This update provides
the corresponding updates for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that Open VM Tools incorrectly handled SAML tokens. A
remote attacker with Guest Operations privileges could possibly use this
issue to elevate their privileges. (CVE-2023-34058)
Matthias Gerstner discovered that Open VM Tools incorrectly handled file
descriptors when dropping privileges. A local attacker could possibly use
this issue to hijack /dev/uinput and simulate user inputs. (CVE-2023-34059)
OSV
open-vm-tools vulnerabilities
osv·2023-10-31·CVSS 7.5
CVE-2023-34058 [HIGH] open-vm-tools vulnerabilities
open-vm-tools vulnerabilities
It was discovered that Open VM Tools incorrectly handled SAML tokens. A
remote attacker Guest Operations privileges could possibly use this issue
to escalate privileges. (CVE-2023-34058)
Matthias Gerstner discovered that Open VM Tools incorrectly handled file
descriptors when dropping privileges. A local attacker could possibly use
this issue to hijack /dev/uinput and simulate user inputs. (CVE-2023-34059)
GHSA
GHSA-q6p8-m5f4-4vmp: open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper
ghsa_unreviewed·2023-10-27
CVE-2023-34059 [HIGH] CWE-404 GHSA-q6p8-m5f4-4vmp: open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the
/dev/uinput file descriptor allowing them to simulate user inputs.
OSV
CVE-2023-34059: open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper
osv·2023-10-27·CVSS 7.0
CVE-2023-34059 [HIGH] CVE-2023-34059: open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2023/10/27/2http://www.openwall.com/lists/oss-security/2023/10/27/3http://www.openwall.com/lists/oss-security/2023/11/26/1http://www.openwall.com/lists/oss-security/2023/11/27/1https://lists.debian.org/debian-lts-announce/2023/11/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/G7G77Z76CQPGUF7VHRA6O3UFCMPPR4O2/https://lists.fedoraproject.org/archives/list/[email protected]/message/MQUOFQL2SNNNMKROQ3TZQY4HEYMNOIBW/https://lists.fedoraproject.org/archives/list/[email protected]/message/WLTKVTRKQW2GD2274H3UOW6XU4E62GSK/https://www.debian.org/security/2023/dsa-5543https://www.vmware.com/security/advisories/VMSA-2023-0024.htmlhttp://www.openwall.com/lists/oss-security/2023/10/27/2http://www.openwall.com/lists/oss-security/2023/10/27/3http://www.openwall.com/lists/oss-security/2023/11/26/1http://www.openwall.com/lists/oss-security/2023/11/27/1https://lists.debian.org/debian-lts-announce/2023/11/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/G7G77Z76CQPGUF7VHRA6O3UFCMPPR4O2/https://lists.fedoraproject.org/archives/list/[email protected]/message/MQUOFQL2SNNNMKROQ3TZQY4HEYMNOIBW/https://lists.fedoraproject.org/archives/list/[email protected]/message/WLTKVTRKQW2GD2274H3UOW6XU4E62GSK/https://www.debian.org/security/2023/dsa-5543https://www.vmware.com/security/advisories/VMSA-2023-0024.htmlhttps://www.openwall.com/lists/oss-security/2023/10/27/3
2023-10-27
Published