Lucene search

K
vmwareVMwareVMSA-2023-0024
HistoryOct 26, 2023 - 12:00 a.m.

VMware Tools updates address Local Privilege Escalation and SAML Token Signature Bypass vulnerabilities (CVE-2023-34057, CVE-2023-34058)

2023-10-2600:00:00
www.vmware.com
21
vmware
tools
updates
local privilege escalation
saml token
signature bypass
vulnerabilities
macos
cve-2023-34057
cve-2023-34058
severity
cvssv3
software

7.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.9%

3a. Local privilege escalation vulnerability in VMware Tools (macOS) (CVE-2023-34057)

VMware Tools contains a local privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.8.

3b. SAML Token Signature Bypass vulnerability in VMware Tools (CVE-2023-34058)

VMware Tools contains a SAML token signature bypass vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.1.

CPENameOperatorVersion
vmware toolslt12.1.1
vmware toolslt12.3.5