SB2023102009 - Multiple privilege escalation vulnerabilities in VMware Fusion
Published: October 20, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Race condition (CVE-ID: CVE-2023-34045)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition that occurs during installation for the first time (the user needs to
drag or copy the application to a folder from the '.dmg' volume) or when
installing an upgrade. A local user can exploit the race and gain root privileges on the system.
2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2023-34046)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an error in application installer that occurs during installation for the first time (the user needs to
drag or copy the application to a folder from the '.dmg' volume) or when
installing an upgrade. A local user can execute arbitrary code with root privileges.
Remediation
Install update from vendor's website.