CVE-2023-20858: High severity vmware carbon black vulnerability
VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious actor with privileged access to the App Control administration console may be able to use specially crafted input allowing access to the underlying server operating system.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20858?
CVE-2023-20858 is classified as a high-severity vulnerability due to its potential exploitation by privileged attackers.
How do I fix CVE-2023-20858?
To fix CVE-2023-20858, you should update VMware Carbon Black App Control to the latest version, 8.7.8 or 8.8.6, or later versions.
Which versions of VMware Carbon Black App Control are affected by CVE-2023-20858?
CVE-2023-20858 affects VMware Carbon Black App Control versions prior to 8.7.8, 8.8.6, and 8.9.4.
Can CVE-2023-20858 be exploited remotely?
CVE-2023-20858 requires privileged access to the App Control administration console for exploitation, hence it cannot be exploited remotely by unauthorized users.
What type of vulnerability is CVE-2023-20858?
CVE-2023-20858 is classified as an injection vulnerability, allowing the input of specially crafted data to gain unauthorized access.