First published: Tue Apr 25 2023(Updated: )
VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Fusion | >=13.0.0<13.0.2 | |
Apple Mac OS X |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20871 is a local privilege escalation vulnerability found in VMware Fusion.
An attacker with read/write access to the host operating system can exploit CVE-2023-20871 to gain root access.
CVE-2023-20871 has a severity rating of 7.8 (High).
VMware Fusion versions between 13.0.0 and 13.0.2 are affected by CVE-2023-20871.
To mitigate CVE-2023-20871, users should update VMware Fusion to a version that is not affected by the vulnerability.