CVE-2023-20867
13.06.2023, 17:15
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vmware | tools | 10.3.0 ≤ 𝑥 < 12.2.5 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
| debian | debian_linux | 12.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| open-vm-tools |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libvmtools-devel |
| ||||||||||||||||||||||||||||||||||||||||||
| libvmtools0 |
| ||||||||||||||||||||||||||||||||||||||||||
| open-vm-tools |
| ||||||||||||||||||||||||||||||||||||||||||
| open-vm-tools-desktop |
| ||||||||||||||||||||||||||||||||||||||||||
| open-vm-tools-salt-minion |
| ||||||||||||||||||||||||||||||||||||||||||
| open-vm-tools-sdmp |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| open-vm-tools |
| ||||||||||||||||||||||||||||||||||
| open-vm-tools-desktop |
| ||||||||||||||||||||||||||||||||||
| open-vm-tools-devel |
| ||||||||||||||||||||||||||||||||||
| open-vm-tools-salt-minion |
| ||||||||||||||||||||||||||||||||||
| open-vm-tools-sdmp |
| ||||||||||||||||||||||||||||||||||
| open-vm-tools-test |
|
Common Weakness Enumeration
References