Improper Authentication in VMware Tools - CVE-2023-20867
Published: June 13, 2023 / Updated: August 27, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in the vgauth module. An attacker who compromised the ESXi host can bypass authentication process and execute privileged commands across Windows, Linux, and PhotonOS (vCenter) guest VMs without authentication of guest credentials from a compromised ESXi host and no default logging on guest VMs.
Note, the vulnerability is being actively exploited in the wild by the UNC3886 APT actor.
Affected software
IBM Qradar SIEM
Oracle Linux
Debian Linux
Amazon Linux AMI
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
CentOS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
Desktop Applications Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
Dell Policy Manager for Secure Connect Gateway (SCG)
open-vm-tools
Storage Defender – Data Protect
open-vm-tools (Ubuntu package)
open-vm-tools (Red Hat package)
open-vm-tools
open-vm-tools-desktop
open-vm-tools-devel
open-vm-tools-test
open-vm-tools (Debian package)
libvmtools0
open-vm-tools-sdmp
open-vm-tools-debuginfo
open-vm-tools-debugsource
open-vm-tools-desktop-debuginfo
open-vm-tools-sdmp-debuginfo
libvmtools0-debuginfo
libvmtools-devel
open-vm-tools-salt-minion
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
RecoverPoint for VMs
Dell EMC VxRail Appliance
RSA Authentication Manager
IBM DataPower Gateway
IBM Security Verify Governance
How to mitigate CVE-2023-20867
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.18.00.00
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
open-vm-tools - update to 12.2.5
open-vm-tools (Ubuntu package) - addressed in versions Ubuntu Pro, 2:11.3.0-2ubuntu0~ubuntu20.04.5, 2:12.1.5-3~ubuntu0.22.04.2, 2:12.1.5-3ubuntu0.23.04.1
Storage Defender – Data Protect - update to 1.3.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
EMC ViPR SRM - update to 4.10.0.0
RecoverPoint for VMs - update to 6.0.SP1.P1
Dell EMC VxRail Appliance - update to 8.0.120
RSA Authentication Manager - addressed in versions 8.7 SP1 Patch 3, 8.7 SP2 Patch 1
IBM DataPower Gateway - addressed in versions 10.0.1.19, 10.5.0.12, 10.6.0.0
IBM Security Verify Governance - update to 10.0.2.0.4
open-vm-tools (Red Hat package) - addressed in versions 11.0.0-4.el8_2.2, 11.0.5-3.el7_9.6, 11.2.0-2.el8_4.2, 11.3.5-1.el8_6.2, 11.3.5-1.el9_0.2, 12.1.5-1.el9_2.1, 12.1.5-2.el8_8
open-vm-tools - addressed in versions 11.0.5-3, 12.1.5-2
open-vm-tools-desktop - addressed in versions 11.0.5-3, 12.1.5-2
open-vm-tools-devel - update to 11.0.5-3
open-vm-tools-test - update to 11.0.5-3
open-vm-tools (Debian package) - addressed in versions 2:11.2.5-2+deb11u2, 2:12.2.0-1+deb12u1
libvmtools0 - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
open-vm-tools-sdmp - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
open-vm-tools-debuginfo - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
open-vm-tools-debugsource - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
open-vm-tools-desktop-debuginfo - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
open-vm-tools-sdmp-debuginfo - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
libvmtools0-debuginfo - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
open-vm-tools - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
libvmtools-devel - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-150300.29.1
open-vm-tools-desktop - addressed in versions 11.3.5-150100.4.37.18.1, 11.3.5-150200.5.16.16.1, 12.2.0-4.53.1, 12.2.0-150300.29.1
open-vm-tools-devel - addressed in versions 12.0.5-3, 12.1.5-2
open-vm-tools-desktop - addressed in versions 12.0.5-3, 12.1.5-2
open-vm-tools-debuginfo - addressed in versions 12.0.5-3, 12.1.5-2
open-vm-tools-test - addressed in versions 12.0.5-3, 12.1.5-2
open-vm-tools-sdmp - addressed in versions 12.0.5-3, 12.1.5-2
open-vm-tools-debugsource - addressed in versions 12.0.5-3, 12.1.5-2
open-vm-tools - addressed in versions 12.0.5-3, 12.1.5-2
open-vm-tools-salt-minion - addressed in versions 12.0.5-3, 12.1.5-2
open-vm-tools-sdmp - update to 12.1.5-2
open-vm-tools-salt-minion - addressed in versions 12.2.0-4.53.1, 12.2.0-150300.29.1
open-vm-tools - update to 12.2.5-1
open-vm-tools - addressed in versions 12.3.0-1.fc37, 12.3.0-1.fc38, 12.3.0-1.fc39
External References
Related Security Bulletins
- Authentication bypass in VMware Tools
- Improper authentication in open-vm-tools
- SUSE update for open-vm-tools
- SUSE update for open-vm-tools
- Red Hat Enterprise Linux 7 update for open-vm-tools
- Red Hat Enterprise Linux 8 update for open-vm-tools
- Red Hat Enterprise Linux 8 update for open-vm-tools
- Red Hat Enterprise Linux 9.0 Extended Update Support update for open-vm-tools
- Red Hat Enterprise Linux 9 update for open-vm-tools
- Red Hat Enterprise Linux 8 update for open-vm-tools
- Red Hat Enterprise Linux 8.6 Extended Update Support update for open-vm-tools
- Multiple vulnerabilities in Oracle Linux
- Ubuntu update for open-vm-tools
- CentOS 7 update for open-vm-tools
- SUSE update for open-vm-tools
- SUSE update for open-vm-tools
- Multiple vulnerabilities in IBM Storage Defender Data Protect
- SUSE update for open-vm-tools
- Debian update for open-vm-tools
- Fedora 39 update for open-vm-tools
- Fedora 38 update for open-vm-tools
- Fedora 37 update for open-vm-tools
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in IBM QRadar SIEM
- openEuler 22.03 LTS update for open-vm-tools
- openEuler 22.03 LTS SP1 update for open-vm-tools
- openEuler 22.03 LTS SP2 update for open-vm-tools
- Improper authentication in IBM DataPower Gateway Virtual Edition
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Multiple vulnerabilities in Dell Secure Connect Gateway Security Policy Manager
- Amazon Linux AMI update for open-vm-tools
- Anolis OS update for open-vm-tools
- Anolis OS update for open-vm-tools
- RSA Authentication Manager update for third-party components
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)