CVE-2023-20867

VMware Tools Authentication Bypass Vulnerability

Basic Information

CVE State
PUBLISHED
Reserved Date
November 01, 2022
Published Date
June 13, 2023
Last Updated
February 13, 2025
Vendor
VMware
Product
VMware Tools
Description
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.

CVSS Scores

CVSS v3.1

3.9 - LOW

Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

SSVC Information

Exploitation
active
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (added 2023-06-23 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2023-06-23 00:00:00 UTC