CVE-2023-20867 is a vulnerability in VMware Tools affecting various Linux distributions, where a fully compromised ESXi host can bypass authentication for host-to-guest operations. This low-severity flaw (CVSS 3.9) has a high attack complexity and requires high privileges on the ESXi host, but can impact the confidentiality and integrity of guest virtual machines. Notably, this vulnerability is actively exploited in the wild, with Mandiant reporting exploitation by UNC3886 since 2021, and it has garnered significant community discussion and media coverage despite no public exploit code being available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.3.0, < 12.2.5CPE matchmatch criteria | cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.