PT-2023-2452 · Vmware · Vmware Fusion+1

Published

2023-04-25

·

Updated

2026-02-27

·

CVE-2023-20869

CVSS v3.1

8.2

High

AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware Workstation versions 17.x VMware Fusion versions 13.x
Description The issue is related to a stack-based buffer-overflow vulnerability in the functionality for sharing host Bluetooth devices with the virtual machine. This vulnerability may allow an attacker to execute arbitrary code. The estimated number of potentially affected devices is not specified. Real-world incidents where this issue was exploited include a demonstration at Pwn2Own 2023 in Vancouver, showcasing a Host-to-Guest escape vulnerability in the VMware Workstation VBluetooth device.
Recommendations For VMware Workstation version 17.x, update the software to a version that contains a fix for this issue. For VMware Fusion version 13.x, update the software to a version that contains a fix for this issue. As a temporary workaround, consider disabling the functionality for sharing host Bluetooth devices with the virtual machine until a patch is available.

Fix

Stack Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-02242
CVE-2023-20869
ZDI-23-522

Affected Products

Vmware Fusion
Vmware Workstation