PT-2023-6347 · Vmware · Vmware Fusion

Patch1T

·

Published

2023-10-20

·

Updated

2025-03-07

·

CVE-2023-34045

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware Fusion versions 13.x prior to 13.5
Description The issue is a local privilege escalation vulnerability that occurs during the first installation of VMware Fusion or when installing an upgrade. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed or being installed for the first time. The vulnerability is related to errors in synchronization when using a shared resource.
Recommendations For versions 13.x prior to 13.5, update to version 13.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the system during the installation or upgrade process to minimize the risk of exploitation. Avoid using the application until the issue is resolved. At the moment, there is no other information about additional mitigation measures.

Fix

Race Condition

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07059
CVE-2023-34045

Affected Products

Vmware Fusion