VMware Tools Authentication Bypass Vulnerability
Summary
| CVE | CVE-2023-20867 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-13 17:15:00 UTC |
| Updated | 2023-10-16 18:15:00 UTC |
| Description | A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. |
Risk And Classification
EPSS: 0.027190000 probability, percentile 0.858750000 (date 2026-04-02)
CISA KEV: Listed on 2023-06-23; due 2023-07-14; ransomware use Unknown
Problem Types: CWE-287
CISA Known Exploited Vulnerability
| Vendor | VMware |
|---|---|
| Product | Tools |
| Name | VMware Tools Authentication Bypass Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://www.vmware.com/security/advisories/VMSA-2023-0013.html; https://nvd.nist.gov/vuln/detail/CVE-2023-20867 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 37 Update: open-vm-tools-12.3.0-1.fc37 - package-announce - Fedora Mailing-Lists | MISC | lists.fedoraproject.org | |
| CVE-2023-20867 VMware Tools Vulnerability in NetApp Products | NetApp Product Security | MISC | security.netapp.com | |
| oss-security - CVE-2023-20867: open-vm-tools: Authentication Bypass vulnerability in the vgauth module | MISC | www.openwall.com | |
| Debian -- Security Information -- DSA-5493-1 open-vm-tools | MISC | www.debian.org | |
| [SECURITY] [DLA 3531-1] open-vm-tools security update | MISC | lists.debian.org | |
| [SECURITY] Fedora 39 Update: open-vm-tools-12.3.0-1.fc39 - package-announce - Fedora Mailing-Lists | MISC | lists.fedoraproject.org | |
| VMSA-2023-0013 | MISC | www.vmware.com | |
| oss-security - Re: CVE-2023-20867: open-vm-tools: Authentication Bypass vulnerability in the vgauth module | MISC | www.openwall.com | |
| [SECURITY] Fedora 38 Update: open-vm-tools-12.3.0-1.fc38 - package-announce - Fedora Mailing-Lists | MISC | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160758 Oracle Enterprise Linux Security Update for open-vm-tools (ELSA-2023-3944)
- 160769 Oracle Enterprise Linux Security Update for open-vm-tools (ELSA-2023-3949)
- 160770 Oracle Enterprise Linux Security Update for open-vm-tools (ELSA-2023-3948)
- 199619 Ubuntu Security Notification for Open VM Tools Vulnerability (USN-6257-1)
- 241768 Red Hat Update for open-vm-tools (RHSA-2023:3949)
- 241769 Red Hat Update for open-vm-tools (RHSA-2023:3947)
- 241770 Red Hat Update for open-vm-tools (RHSA-2023:3948)
- 241771 Red Hat Update for open-vm-tools (RHSA-2023:3946)
- 241772 Red Hat Update for open-vm-tools (RHSA-2023:3944)
- 241773 Red Hat Update for open-vm-tools (RHSA-2023:3950)
- 241774 Red Hat Update for open-vm-tools (RHSA-2023:3945)
- 257243 CentOS Security Update for open-vm-tools (CESA-2023:3944)
- 284506 Fedora Security Update for open (FEDORA-2023-df375d0634)
- 284529 Fedora Security Update for open (FEDORA-2023-9b1a1023ac)
- 285262 Fedora Security Update for open (FEDORA-2023-20b6ac4b6c)
- 355586 Amazon Linux Security Advisory for open-vm-tools : ALAS2-2023-2139
- 355637 Amazon Linux Security Advisory for open-vm-tools : ALAS2023-2023-259
- 378578 VMware Tools Authentication Bypass Vulnerability (VMSA-2023-0013)
- 378711 Alibaba Cloud Linux Security Update for open-vm-tools (ALINUX3-SA-2023:0076)
- 378763 Alibaba Cloud Linux Security Update for open-vm-tools (ALINUX2-SA-2023:0031)
- 506132 Alpine Linux Security Update for open-vm-tools
- 6000023 Debian Security Update for open-vm-tools (DSA 5493-1)
- 6000029 Debian Security Update for open-vm-tools (DLA 3531-1)
- 6140302 AWS Bottlerocket Security Update for open-vm-tools (GHSA-hm65-gmgh-7m83)
- 754102 SUSE Enterprise Linux Security Update for open-vm-tools (SUSE-SU-2023:2530-1)
- 754124 SUSE Enterprise Linux Security Update for open-vm-tools (SUSE-SU-2023:2604-1)
- 941174 AlmaLinux Security Update for open-vm-tools (ALSA-2023:3949)
- 941176 AlmaLinux Security Update for open-vm-tools (ALSA-2023:3948)
- 960953 Rocky Linux Security Update for open-vm-tools (RLSA-2023:3948)
- 960956 Rocky Linux Security Update for open-vm-tools (RLSA-2023:3949)