CVE-2023-34059: - File Descriptor Hijack vulnerability in open-vm-tools
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.
Other sources
VMware Tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2023-34059?
CVE-2023-34059 has a medium severity rating due to its potential to allow non-root users to hijack file descriptors.
How do I fix CVE-2023-34059?
To mitigate CVE-2023-34059, update open-vm-tools to the latest version available for your Linux distribution.
Which versions of open-vm-tools are affected by CVE-2023-34059?
CVE-2023-34059 affects multiple versions of open-vm-tools below 2:12.3.0 and can vary across different Linux distributions.
Who is the vendor of the software affected by CVE-2023-34059?
The vendor of the affected software in CVE-2023-34059 is VMware.
What type of vulnerability is CVE-2023-34059?
CVE-2023-34059 is a file descriptor hijack vulnerability in the vmware-user-suid-wrapper.