CVE-2023-20900: [Security Advisory] open-vm-tools: SAML token signature bypass vulnerability (CVE-2023-20900)
A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
Other sources
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor with man-in-the-middle (MITM) network positioning between vCenter server and the virtual machine may be able to bypass SAML token signature verification, to perform VMware Tools Guest Operations.
References:
https://www.vmware.com/security/advisories/VMSA-2023-0019.html https://www.openwall.com/lists/oss-security/2023/08/31/1 https://github.com/vmware/open-vm-tools/blob/CVE-2023-20900.patch/CVE-2023-20900.patch
— Red Hat
VMware Tools could allow a remote attacker to bypass security restrictions, caused by improper SAML token signature verification. By utilize man-in-the-middle attack techniques, an attacker could exploit this vulnerability to perform VMware Tools Guest Operations
— IBM
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this security advisory?
The vulnerability ID of this security advisory is CVE-2023-20900.
What is the severity of CVE-2023-20900?
CVE-2023-20900 has a severity value of 7.5, which is classified as high.
What is the affected software for CVE-2023-20900?
The affected software for CVE-2023-20900 includes open-vm-tools with various versions.
How can I fix the vulnerability CVE-2023-20900?
To fix CVE-2023-20900, make sure to update open-vm-tools to the recommended versions provided by the software vendor.
Where can I find more information about CVE-2023-20900?
More information about CVE-2023-20900 can be found at the following references: [link1], [link2], [link3].