Information disclosure vulnerability in bluetooth device-sharing functionality
CVE-2023-34044

6MEDIUM

Key Information:

Vendor
VMware
Vendor
CVE Published:
20 October 2023

Summary

VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.

Affected Version(s)

Fusion MacOS 13.x < 13.5

Workstation Windows 17.x < 17.5

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.