Junglewise Threat Intelligence

CVE-2023-20867: VMware Tools Authentication Bypass Vulnerability

CVE-2023-20867 · Severity: critical · CVSS 3.9 · Exploited in the wild · Published 2023-06-23

Technologies: VMware ESXi. Vendors: VMware.

Executive brief

VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can bypass authentication for host-to-guest operations, allowing an attacker with root access on the host to impact the confidentiality and integrity of the guest virtual machine.

Affected products

  • VMware VMware Tools
  • VMware ESXi

Timeline

  • 2023-06-23: disclosed
  • 2023-06-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-06-23: exploited: Reported as exploited in the wild at time of publication.