CVE-2023-20867

CVE Published 2023-06-13
Related CWE(s) CWE-287: Improper Authentication
Related Vendor(s) fedoraproject, vmware, debian
Related Product(s) fedora, tools, debian_linux
Exploitation Reported (CISA KEV) 2023-06-23
CVSS 3 Base Score 3.9 (LOW)
CVSS 3 Attack Complexity HIGH
CVSS 3 Attack Vector LOCAL

A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Threat Reports Related to CVE-2023-20867

Report

Cloaked and Covert: Uncovering UNC3886 Espionage Operations

This article by researchers from Google's Mandiant outlines intrusion activity by UNC3886, a suspected China-nexus cyber espionage group. The ...

Report

We're All in this Together - A Year in Review of Zero-Days Exploited In-the-Wild in 2023

This report from Mandiant and Google Threat Analysis Group (TAG) presents combined analysis of zero day vulnerability exploitation in 2023. The ...

Associated CAPEC Patterns

References