PT-2023-3080 · Vmware+10 · Photonos+13

Solar Designer

·

Published

2023-06-13

·

Updated

2026-01-05

·

CVE-2023-20867

CVSS v3.1

3.9

Low

VectorAV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions VMware Tools versions prior to 12.2.5 VMware vCenter (affected versions not specified)
Description A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. The vulnerability is related to errors in the authentication procedure of the vgauth module in VMware Tools. Exploitation of this issue may allow an attacker to affect the confidentiality and integrity of protected information. Chinese state-sponsored group UNC3886 has been exploiting this vulnerability since 2021 to backdoor Windows, Linux, and PhotonOS systems.
Recommendations For VMware Tools versions prior to 12.2.5, update to version 12.2.5 or later to resolve the issue. For VMware vCenter, update to the latest version to account for this vulnerability. As a temporary workaround, consider restricting access to the vulnerable vgauth module until a patch is available. Avoid using the vulnerable authentication mechanism in host-to-guest operations until the issue is resolved. At the moment, there is no additional information about other mitigation measures.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

ALSA-2023:3948
ALSA-2023:3949
ALT-PU-2023-1989
ALT-PU-2023-4334
ALT-PU-2023-5642
ALT-PU-2024-1233
BDU:2023-03162
CESA-2023_3944
CESA-2023_3949
CVE-2023-20867
DLA-3531-1
DSA-5493-1
MGASA-2024-0058
OESA-2023-1629
OESA-2023-1630
OESA-2023-1631
OPENSUSE-SU-2024:13022-1
RHSA-2023:3944
RHSA-2023:3945
RHSA-2023:3946
RHSA-2023:3947
RHSA-2023:3948
RHSA-2023:3949
RHSA-2023:3950
RHSA-2023_3944
RHSA-2023_3948
RHSA-2023_3949
RLSA-2023:3948
RLSA-2023:3949
ROSA-SA-2023-2201
SUSE-SU-2023:2530-1
SUSE-SU-2023:2604-1
SUSE-SU-2023:2604-2
SUSE-SU-2023:3504-1
SUSE-SU-2023:3505-1
SUSE-SU-2023_2530-1
SUSE-SU-2023_2604-1
SUSE-SU-2023_2604-2
SUSE-SU-2023_3504-1
SUSE-SU-2023_3505-1
USN-6257-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Esxi
Linuxmint
Photonos
Red Hat
Rocky Linux
Suse
Ubuntu
Vmware Tools
Vmware Vcenter
Windows