PT-2023-1294 · Vmware · Vmware Workstation

Frederik Reiter

·

Published

2023-02-02

·

Updated

2025-03-26

·

CVE-2023-20854

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware Workstation (affected versions not specified)
Description The issue is related to errors in access control, allowing a malicious actor with local user privileges to delete arbitrary files from the file system of the machine on which the software is installed. This can be exploited by an attacker to remove files in the root operating system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00571
CVE-2023-20854

Affected Products

Vmware Workstation