Skip to main content

VMware Releases Critical Security Update

Critical security advisory addresses four vulnerabilities in VMware Workstation and VMware Fusion

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Critical security advisory addresses four vulnerabilities in VMware Workstation and VMware Fusion


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

VMware has released security updates to address multiple vulnerabilities in VMware Workstation Pro/Player and VMware Fusion. Both platforms are affected by CVE-2023-20869, a critical stack-based buffer-overflow vulnerability in the functionality for sharing host Bluetooth devices with virtual machines. A malicious attacker with local administrative privileges on a virtual machine could exploit this vulnerability to execute code.

CVE-2023-20870 is an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine in both VMware Workstation Pro/Player and VMware Fusion. By exploiting this vulnerability, a malicious attacker with local administrative privileges on a virtual machine could be able to read privileged information contained in hypervisor memory.

CVE-2023-20869 and CVE-2023-20870 leveraged as part of exploit chain

CVE-2023-20869 and CVE-2023-20870 were part of an exploit chain demonstrated by security researchers at Pwn2Own Vancouver 2023. Technical details of this exploit chain will be released 90 days after the event.


Remediation advice

Affected organisations are encouraged to review the VMware Security Advisory VMSA-2023-0008 and apply any relevant updates.



Last edited: 26 April 2023 3:51 pm