Skip to content
COOEY

EXPOSURES › CVE-2023-20867

CVE-2023-20867

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-06-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-20867 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

VMware Tools Authentication Bypass Vulnerability

VMware Tools contains an authentication bypass vulnerability in the vgauth module, allowing an attacker with root access over ESXi to compromise guest virtual machines. This impacts the confidentiality and integrity of the guest VMs and should be patched immediately.

Shame score — The vulnerability is actively exploited and allows for authentication bypass, impacting guest VMs' confidentiality and integrity.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized