Improper Authentication in VMware Tools - CVE-2023-20867

 

Improper Authentication in VMware Tools - CVE-2023-20867

Published: June 13, 2023 / Updated: August 27, 2024


Vulnerability identifier: #VU77208
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20867
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in the vgauth module. An attacker who compromised the ESXi host can bypass authentication process and execute privileged commands across Windows, Linux, and PhotonOS (vCenter) guest VMs without authentication of guest credentials from a compromised ESXi host and no default logging on guest VMs.

Note, the vulnerability is being actively exploited in the wild by the UNC3886 APT actor.


Affected software

VMware Tools
IBM Qradar SIEM
Oracle Linux
Debian Linux
Amazon Linux AMI
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
CentOS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
Desktop Applications Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
Dell Policy Manager for Secure Connect Gateway (SCG)
open-vm-tools
Storage Defender – Data Protect
open-vm-tools (Ubuntu package)
open-vm-tools (Red Hat package)
open-vm-tools
open-vm-tools-desktop
open-vm-tools-devel
open-vm-tools-test
open-vm-tools (Debian package)
libvmtools0
open-vm-tools-sdmp
open-vm-tools-debuginfo
open-vm-tools-debugsource
open-vm-tools-desktop-debuginfo
open-vm-tools-sdmp-debuginfo
libvmtools0-debuginfo
libvmtools-devel
open-vm-tools-salt-minion
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
RecoverPoint for VMs
Dell EMC VxRail Appliance
RSA Authentication Manager
IBM DataPower Gateway
IBM Security Verify Governance

How to mitigate CVE-2023-20867

Install updates from vendor's website.

VMware Tools - update to 12.2.5
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.18.00.00
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
open-vm-tools - update to 12.2.5
open-vm-tools (Ubuntu package) - addressed in versions Ubuntu Pro, 2:11.3.0-2ubuntu0~ubuntu20.04.5, 2:12.1.5-3~ubuntu0.22.04.2, 2:12.1.5-3ubuntu0.23.04.1
Storage Defender – Data Protect - update to 1.3.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
EMC ViPR SRM - update to 4.10.0.0
RecoverPoint for VMs - update to 6.0.SP1.P1
Dell EMC VxRail Appliance - update to 8.0.120
RSA Authentication Manager - addressed in versions 8.7 SP1 Patch 3, 8.7 SP2 Patch 1
IBM DataPower Gateway - addressed in versions 10.0.1.19, 10.5.0.12, 10.6.0.0
IBM Security Verify Governance - update to 10.0.2.0.4
open-vm-tools (Red Hat package) - addressed in versions 11.0.0-4.el8_2.2, 11.0.5-3.el7_9.6, 11.2.0-2.el8_4.2, 11.3.5-1.el8_6.2, 11.3.5-1.el9_0.2, 12.1.5-1.el9_2.1, 12.1.5-2.el8_8
open-vm-tools - addressed in versions 11.0.5-3, 12.1.5-2
open-vm-tools-desktop - addressed in versions 11.0.5-3, 12.1.5-2
open-vm-tools-devel - update to 11.0.5-3
open-vm-tools-test - update to 11.0.5-3
open-vm-tools (Debian package) - addressed in versions 2:11.2.5-2+deb11u2, 2:12.2.0-1+deb12u1
libvmtools0 - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
open-vm-tools-sdmp - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
open-vm-tools-debuginfo - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
open-vm-tools-debugsource - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
open-vm-tools-desktop-debuginfo - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
open-vm-tools-sdmp-debuginfo - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
libvmtools0-debuginfo - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
open-vm-tools - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
libvmtools-devel - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-150300.29.1
open-vm-tools-desktop - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
open-vm-tools-devel - addressed in versions 12.0.5-3, 12.1.5-2
open-vm-tools-desktop - addressed in versions 12.0.5-3, 12.1.5-2
open-vm-tools-debuginfo - addressed in versions 12.0.5-3, 12.1.5-2
open-vm-tools-test - addressed in versions 12.0.5-3, 12.1.5-2
open-vm-tools-sdmp - addressed in versions 12.0.5-3, 12.1.5-2
open-vm-tools-debugsource - addressed in versions 12.0.5-3, 12.1.5-2
open-vm-tools - addressed in versions 12.0.5-3, 12.1.5-2
open-vm-tools-salt-minion - addressed in versions 12.0.5-3, 12.1.5-2
open-vm-tools-sdmp - update to 12.1.5-2
open-vm-tools-salt-minion - addressed in versions 12.2.0-4.53.1, 12.2.0-150300.29.1
open-vm-tools - update to 12.2.5-1
open-vm-tools - addressed in versions 12.3.0-1.fc37, 12.3.0-1.fc38, 12.3.0-1.fc39

External References

Related Security Bulletins