Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-20867
HistoryJun 13, 2023 - 12:00 a.m.

CVE-2023-20867

2023-06-1300:00:00
ubuntu.com
ubuntu.com
157
esxi host
vmware tools
host-to-guest operations
confidentiality
integrity
guest virtual machine

3.9 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

0.005 Low

EPSS

Percentile

76.5%

A fully compromised ESXi host can force VMware Tools to fail to
authenticate host-to-guest operations, impacting the confidentiality and
integrity of the guest virtual machine.

Notes

Author Note
mdeslaur per upstream, this is a low-severity issue an attacker must have root access on the host to exploit the guest, which doesn’t really give any extra privileges
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchopen-vm-tools< 2:11.0.5-4ubuntu0.18.04.3+esm1UNKNOWN
ubuntu20.04noarchopen-vm-tools< 2:11.3.0-2ubuntu0~ubuntu20.04.5UNKNOWN
ubuntu22.04noarchopen-vm-tools< 2:12.1.5-3~ubuntu0.22.04.2UNKNOWN
ubuntu23.04noarchopen-vm-tools< 2:12.1.5-3ubuntu0.23.04.1UNKNOWN
ubuntu16.04noarchopen-vm-tools< 2:10.2.0-3~ubuntu0.16.04.1+esm2UNKNOWN

3.9 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

0.005 Low

EPSS

Percentile

76.5%