CVE-2023-20870: Medium severity vmware fusion vulnerability
Published Apr 25, 2023
·Updated
VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
Affected Software
2 affected components
VMware Fusion>=13.0.0<13.0.2
VMware Workstation>=17.0.0<17.0.2
Event History
Apr 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this VMware Workstation and Fusion vulnerability?
The vulnerability ID for this VMware Workstation and Fusion vulnerability is CVE-2023-20870.
2
What is the description of the VMware Workstation and Fusion vulnerability?
The vulnerability is an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine in VMware Workstation and Fusion.
3
Which software products are affected by this vulnerability?
VMware Workstation and VMware Fusion are affected by this vulnerability.
4
What is the severity of the VMware Workstation and Fusion vulnerability?
The severity of the VMware Workstation and Fusion vulnerability is medium.
5
How can I fix the VMware Workstation and Fusion vulnerability?
To fix the vulnerability, update your VMware Workstation or Fusion software to versions 13.0.2 or 17.0.2 respectively.