#VU82271 Permissions, Privileges, and Access Controls in VMware Fusion - CVE-2023-34046

 

#VU82271 Permissions, Privileges, and Access Controls in VMware Fusion - CVE-2023-34046

Published: October 20, 2023


Vulnerability identifier: #VU82271
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-34046
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
VMware Fusion
Software vendor:
VMware, Inc

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an error in application installer that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrade. A local user can execute arbitrary code with root privileges.


Remediation

Install updates from vendor's website.

External links