File Descriptor Hijack Vulnerability in Open-vm-tools by VMware
CVE-2023-34059
7HIGH
What is CVE-2023-34059?
The open-vm-tools package contains a potential vulnerability within the vmware-user-suid-wrapper component. A threat actor with non-root privileges may exploit this vulnerability to intercept and manipulate the /dev/uinput file descriptor, thereby simulating user inputs. This could lead to malicious control over the host environment, allowing unauthorized actions and user impersonations.
Affected Version(s)
open-vm-tools Linux 11.0.0 <= 12.3.0