USN-6463-1: Open VM Tools vulnerabilities
It was discovered that Open VM Tools incorrectly handled SAML tokens. A remote attacker Guest Operations privileges could possibly use this issue to escalate privileges. (CVE-2023-34058) Matthias Gerstner discovered that Open VM Tools incorrectly handled file descriptors when dropping privileges. A local attacker could possibly use this issue to hijack /dev/uinput and simulate user inputs. (CVE-2023-34059)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
CVE-2023-34058
What software is affected by the vulnerability?
Open VM Tools
How can the vulnerability be exploited?
A remote attacker with Guest Operations privileges could possibly use this issue to escalate privileges.
How can I fix the vulnerability?
Update to version 2:12.3.0-1ubuntu0.1 of open-vm-tools package.
Where can I find more information about the vulnerability?
You can find more information about the vulnerability at the following references: CVE-2023-34059, CVE-2023-34058, and the Ubuntu security advisory.