VMware Workstation and Fusion Buffer Overflow Vulnerability

CVE-2023-20869
8.2HIGH

Key Information

Vendor
Vmware
Status
VMware Workstation Pro / Player (Workstation) and VMware Fusion
Vendor
CVE Published:
25 April 2023

Badges

👾 Exploit Exists📰 News Worthy

Summary

The CVE-2023-20869 is a critical stack-based buffer overflow vulnerability found in VMware Workstation and Fusion products that could allow a malicious actor with local admin privileges to execute code on the virtual machine's VMX process running on the host. The vulnerability has been patched by VMware, along with three other security vulnerabilities. It was also exploited during the Pwn2Own Vancouver event, earning the contestant $80,000. The patch for the vulnerability was released in late April, and organizations are urged to update their affected products promptly to mitigate the risk of exploitation. The exploitation of the vulnerability could result in unauthorized access and control over affected systems, with potential impacts including data breaches, system compromise, and further spread of malware.

Affected Version(s)

VMware Workstation Pro / Player (Workstation) and VMware Fusion = VMware Workstation (17.x) and VMware Fusion (13.x)

News Articles

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit exists.

  • First article discovered by Help Net Security

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database4 News Article(s)
.