Stack-based buffer overflow in VMware Workstation and VMware Fusion - CVE-2023-20869
Published: April 25, 2023 / Updated: May 2, 2023
VMware Workstation
VMware Fusion
VMware, Inc
Description
The vulnerability allows an attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the UHCI component in the functionality for sharing host Bluetooth devices with the virtual machine. An attacker with administrative account on the guest OS can trigger a stack-based buffer overflow and execute arbitrary code as the virtual machine's VMX process running on the host.