CVE-2023-20871 is a local privilege escalation vulnerability in VMware Fusion, affecting both Apple macOS and VMware Fusion products. An attacker with read/write access to the host operating system can leverage this flaw to gain root privileges on the host. Rated 7.8 HIGH, this vulnerability has a low attack complexity and requires local user privileges, but can lead to complete compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, the vulnerability has garnered significant community discussion and media coverage, including reports of it being used in a Pwn2Own contest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0.0, < 13.0.2CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.