PT-2023-6347 · Vmware · Vmware Fusion
Patch1T
·
Published
2023-10-20
·
Updated
2025-03-07
·
CVE-2023-34045
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VMware Fusion versions 13.x prior to 13.5
Description
The issue is a local privilege escalation vulnerability that occurs during the first installation of VMware Fusion or when installing an upgrade. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed or being installed for the first time. The vulnerability is related to errors in synchronization when using a shared resource.
Recommendations
For versions 13.x prior to 13.5, update to version 13.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the system during the installation or upgrade process to minimize the risk of exploitation. Avoid using the application until the issue is resolved. At the moment, there is no other information about additional mitigation measures.
Fix
Race Condition
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vmware Fusion