KEVIntel
3.9
CVSS
Low

CVE-2023-20867

PUBLISHED

VMware Tools Authentication Bypass Vulnerability

Exploited in the wild No user interaction
Vendor
VMware
Product
VMware Tools
Published
Jun 13, 2023
EPSS

Description

A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.

cisa nessus_scanner

CVSS scores

CVSS v3.1 3.9 Low

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

Exploitation status

Exploited in the wild

Recorded 2023-06-23 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jun 23, 2023

Scanner integrations

Scanner Reference Detected
Nessus https://www.tenable.com/plugins/nessus/236370 Jun 02, 2025

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nessus