CVE-2023-20867
CVE Published | 2023-06-13 |
---|---|
Related CWE(s) | CWE-287: Improper Authentication |
Related Vendor(s) | fedoraproject, vmware, debian |
Related Product(s) | fedora, tools, debian_linux |
Exploitation Reported (CISA KEV) | 2023-06-23 |
CVSS 3 Base Score | 3.9 (LOW) |
CVSS 3 Attack Complexity | HIGH |
CVSS 3 Attack Vector | LOCAL |
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph
Threat Reports Related to CVE-2023-20867
Report
Cloaked and Covert: Uncovering UNC3886 Espionage Operations
This article by researchers from Google's Mandiant outlines intrusion activity by UNC3886, a suspected China-nexus cyber espionage group. The ...
Report
We're All in this Together - A Year in Review of Zero-Days Exploited In-the-Wild in 2023
This report from Mandiant and Google Threat Analysis Group (TAG) presents combined analysis of zero day vulnerability exploitation in 2023. The ...