Lucene search

K
cvelistVmwareCVELIST:CVE-2023-34044
HistoryOct 20, 2023 - 8:56 a.m.

CVE-2023-34044 Information disclosure vulnerability in bluetooth device-sharing functionality

2023-10-2008:56:53
vmware
www.cve.org
cve-2023-34044
bluetooth device-sharing
out-of-bounds read
local administrative privileges
hypervisor memory

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

16.1%

VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds
read vulnerability that exists in the functionality for sharing host
Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual
machine may be able to read privileged information contained in
hypervisor memory from a virtual machine.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows",
      "MacOS",
      "Linux",
      "iOS",
      "Android",
      "x86",
      "ARM",
      "64 bit",
      "32 bit"
    ],
    "product": "Workstation",
    "vendor": "VMware",
    "versions": [
      {
        "lessThan": "17.5",
        "status": "affected",
        "version": "17.x",
        "versionType": "17.5"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "MacOS"
    ],
    "product": "Fusion",
    "vendor": "VMware",
    "versions": [
      {
        "lessThan": "13.5",
        "status": "affected",
        "version": "13.x",
        "versionType": "13.5"
      }
    ]
  }
]

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

16.1%

Related for CVELIST:CVE-2023-34044