VMware Releases Critical Security Update
Critical security advisory addresses four vulnerabilities in VMware Workstation and VMware Fusion
Summary
Critical security advisory addresses four vulnerabilities in VMware Workstation and VMware Fusion
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
VMware has released security updates to address multiple vulnerabilities in VMware Workstation Pro/Player and VMware Fusion. Both platforms are affected by CVE-2023-20869, a critical stack-based buffer-overflow vulnerability in the functionality for sharing host Bluetooth devices with virtual machines. A malicious attacker with local administrative privileges on a virtual machine could exploit this vulnerability to execute code.
CVE-2023-20870 is an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine in both VMware Workstation Pro/Player and VMware Fusion. By exploiting this vulnerability, a malicious attacker with local administrative privileges on a virtual machine could be able to read privileged information contained in hypervisor memory.
CVE-2023-20869 and CVE-2023-20870 leveraged as part of exploit chain
CVE-2023-20869 and CVE-2023-20870 were part of an exploit chain demonstrated by security researchers at Pwn2Own Vancouver 2023. Technical details of this exploit chain will be released 90 days after the event.
Remediation advice
Affected organisations are encouraged to review the VMware Security Advisory VMSA-2023-0008 and apply any relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 26 April 2023 3:51 pm