CVE-2023-20867
Last modified
CVE-2023-20867 is a low-severity vulnerability rated 3.9/10 on the CVSS scale. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.. CISA has confirmed active exploitation in the wild. EPSS estimates a 13.64% chance of exploitation in the next 30 days.
Description
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Tools | >= 10.3.0, < 12.2.5 |
| Debian | Debian Linux | 10.0 |
| Debian | Debian Linux | 11.0 |
| Debian | Debian Linux | 12.0 |
| Fedoraproject | Fedora | 37 |
| Fedoraproject | Fedora | 38 |
| Fedoraproject | Fedora | 39 |
References
- https://www.openwall.com/lists/oss-security/2023/10/16/11Mailing List, Patch
- https://www.openwall.com/lists/oss-security/2023/10/16/2Mailing List, Patch
- https://lists.debian.org/debian-lts-announce/2023/08/msg00020.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230725-0001/Third Party Advisory
- https://www.debian.org/security/2023/dsa-5493Mailing List, Third Party Advisory
- https://www.vmware.com/security/advisories/VMSA-2023-0013.htmlPatch, Vendor Advisory
- https://www.openwall.com/lists/oss-security/2023/10/16/11Mailing List, Patch
- https://www.openwall.com/lists/oss-security/2023/10/16/2Mailing List, Patch
- https://lists.debian.org/debian-lts-announce/2023/08/msg00020.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230725-0001/Third Party Advisory
- https://www.debian.org/security/2023/dsa-5493Mailing List, Third Party Advisory
- https://www.vmware.com/security/advisories/VMSA-2023-0013.htmlPatch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-20867US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-20867?
How severe is CVE-2023-20867?
How do I fix CVE-2023-20867?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-20861In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, …6.5
- CVE-2023-20862In Spring Security, versions 5.7.x prior to 5.7.8, versions …6.3
- CVE-2023-20863In spring framework versions prior to 5.2.24 release+ ,5.3.2…6.5
- CVE-2023-20864VMware Aria Operations for Logs contains a deserialization v…9.8
- CVE-2023-20865VMware Aria Operations for Logs contains a command injection…7.2
- CVE-2023-20866In Spring Session version 3.0.0, the session id can be logge…6.5
- CVE-2023-20868NSX-T contains a reflected cross-site scripting vulnerabilit…6.1
- CVE-2023-20869VMware Workstation (17.x) and VMware Fusion (13.x) contain a…8.2
- CVE-2023-2087The Essential Blocks plugin for WordPress is vulnerable to C…4.3
- CVE-2023-20870VMware Workstation and Fusion contain an out-of-bounds read …6
- CVE-2023-20871VMware Fusion contains a local privilege escalation vulnerab…7.8
- CVE-2023-20872VMware Workstation and Fusion contain an out-of-bounds read/…8.8
Are you affected by CVE-2023-20867?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
