CVE-2023-20872: High severity vmware fusion vulnerability
Published Apr 25, 2023
·Updated
VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.
Affected Software
5 affected components
All of the following
vmware Fusion=13.0.0
Apple iOS and macOS
VMware Workstation=17.0.0
vmware Fusion=13.0.0
Apple iOS and macOS
Event History
Apr 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-20872.
2
What is the severity level of CVE-2023-20872?
The severity level of CVE-2023-20872 is high with a severity value of 8.8.
3
Which software is affected by CVE-2023-20872?
VMware Fusion 13.0.0 and VMware Workstation 17.0.0 are affected by CVE-2023-20872.
4
What is the description of CVE-2023-20872?
CVE-2023-20872 is an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation in VMware Workstation and Fusion.
5
How can I fix CVE-2023-20872?
To fix CVE-2023-20872, update VMware Workstation to version 17.0.1 or later, and update VMware Fusion to version 13.0.1 or later.