CVE-2023-20867: VMware Tools Authentication Bypass Vulnerability
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
Other sources
Embargo Info ============================================================== The information contained in this email is under embargo until the scheduled public disclosure on June 13th, 2023. The disclosure will be published at https://www.vmware.com/security/advisories/VMSA-2023-0013 at this time.
Description ============================================================== CVE-2023-20867: VMware Tools contains an Authentication Bypass vulnerability in the vgauth module. VMware has evaluated the severity of this issue to be in the Low severity range with a maximum CVSSv3.1 base score of 3.9 - CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N.
Known Attack Vectors ============================================================== A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the virtual machine.
Remediation ============================================================== CVE-2023-20867.zip PASSWORD: 6ljsyoo7l8qenbn4a03q
The following patches are provided for released versions of open-vm-tools:
For releases 12.2.0, 12.1.5, 12.1.0, 12.0.5, 12.0.0, 11.3.5, 11.3.0
2023-20867-Remove-some-dead-code.patch
For releases 11.1.0, 11.1.5, 11.2.0, 11.2.5
2023-20867-Remove-some-dead-code-1110-1125.patch
For releases 11.0.0, 11.0.5
2023-20867-Remove-some-dead-code-1100-1105.patch
For releases 10.3.0, 10.3.5, 10.3.10
2023-20867-Remove-some-dead-code-1030-10310.patch
The patches have been tested against the above open-vm-tools releases. Each applies cleanly with:
git am for a git repository. patch -p2 in the top directory of an open-vm-tools source tree. ==============================================================
— Red Hat
VMware Tools could allow a local authenticated attacker to bypass security restrictions, caused by the failure to authenticate host-to-guest operations in the vgauth module. An attacker could exploit this vulnerability using a fully compromised ESXi host to bypass authentication and obtain access to the guest virtual machine.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/open-vm-toolsto a version that resolves this vulnerability.Fixed in 12.2.5 - Upgrade
Upgrade
ubuntu/open-vm-toolsto a version that resolves this vulnerability.Fixed in 2:10.2.0-3~ubuntu0.16.04.1+ - Upgrade
Upgrade
ubuntu/open-vm-toolsto a version that resolves this vulnerability.Fixed in 2:12.1.5-3~ubuntu0.22.04.2 - Upgrade
Upgrade
ubuntu/open-vm-toolsto a version that resolves this vulnerability.Fixed in 2:12.1.5-3ubuntu0.23.04.1 - Upgrade
Upgrade
ubuntu/open-vm-toolsto a version that resolves this vulnerability.Fixed in 2:11.0.5-4ubuntu0.18.04.3+ - Upgrade
Upgrade
ubuntu/open-vm-toolsto a version that resolves this vulnerability.Fixed in 2:11.3.0-2ubuntu0~ubuntu20.04.5 - Upgrade
Upgrade
debian/open-vm-toolsto a version that resolves this vulnerability.Fixed in 2:10.3.10-1+deb10u6Fixed in 2:11.2.5-2+deb11u3Fixed in 2:12.2.0-1+deb12u2Fixed in 2:12.3.5-4 - Upgrade
Upgrade
debian/open-vm-toolsto a version that resolves this vulnerability.Fixed in 2:10.3.10-1+deb10u6 - Upgrade
Upgrade
debian/open-vm-toolsto a version that resolves this vulnerability.Fixed in 2:11.2.5-2+deb11u3 - Upgrade
Upgrade
debian/open-vm-toolsto a version that resolves this vulnerability.Fixed in 2:12.2.0-1+deb12u2 - Upgrade
Upgrade
debian/open-vm-toolsto a version that resolves this vulnerability.Fixed in 2:12.3.5-4 - Upgrade
Upgrade
open-vm-toolsto a version that resolves this vulnerability.Patch 2023-20867-Remove-some-dead-code-1030-10310.patch - Upgrade
Upgrade
open-vm-toolsto a version that resolves this vulnerability.Patch 2023-20867-Remove-some-dead-code-1100-1105.patch - Upgrade
Upgrade
open-vm-toolsto a version that resolves this vulnerability.Patch 2023-20867-Remove-some-dead-code-1110-1125.patch - Upgrade
Upgrade
open-vm-toolsto a version that resolves this vulnerability.Patch 2023-20867-Remove-some-dead-code.patch - Upgrade
Upgrade
open-vm-toolsto a version that resolves this vulnerability.Patch VMSA-2023-0013 - Operational
Apply the provided patch files using 'git am' when working in a git repository (use 'git am' to apply the patch series).
- Operational
Apply the provided patch files to an open-vm-tools source tree using 'patch -p2' in the top directory of the source tree.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-20867?
CVE-2023-20867 is a vulnerability in VMware Tools that allows a fully compromised ESXi host to force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
Which software is affected by CVE-2023-20867?
VMware Tools is affected by CVE-2023-20867.
What is the severity of CVE-2023-20867?
CVE-2023-20867 has a severity value of 3.9 (low).
How can I fix CVE-2023-20867?
To fix CVE-2023-20867, update VMware Tools to version 2:10.2.0-3~ubuntu0.16.04.1+ (for Ubuntu), 12.2.5 (for Red Hat), or the recommended versions for other distributions.
Where can I find more information about CVE-2023-20867?
You can find more information about CVE-2023-20867 in the VMware Security Advisory VMSA-2023-0013.