CVE-2023-20869: High severity vmware fusion vulnerability
Published Apr 25, 2023
·Updated
VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
Affected Software
2 affected components
VMware Fusion>=13.0.0<13.0.2
VMware Workstation>=17.0.0<17.0.2
Event History
Apr 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-20869.
2
What is the severity of CVE-2023-20869?
The severity of CVE-2023-20869 is high.
3
Which software versions are affected by CVE-2023-20869?
VMware Workstation versions 17.0.0 to 17.0.2 and VMware Fusion versions 13.0.0 to 13.0.2 are affected by CVE-2023-20869.
4
What is the description of CVE-2023-20869?
CVE-2023-20869 is a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine in VMware Workstation and VMware Fusion.
5
How can I fix CVE-2023-20869?
Please refer to the VMware Security Advisory VMSA-2023-0008 for instructions on fixing CVE-2023-20869.