CVE-2023-20879: Medium severity vmware vcenter server and cloud foundation vulnerability
Published May 12, 2023
·Updated
VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system.
Affected Software
12 affected components
VMware Cloud Foundation>=4.0<=4.5
VMware vRealize Operations=8.6.0
VMware vRealize Operations=8.6.0-hotfix1
VMware vRealize Operations=8.6.0-hotfix2
VMware vRealize Operations=8.6.0-hotfix4
VMware vRealize Operations=8.6.0-hotfix5
VMware vRealize Operations=8.6.0-hotfix6
VMware vRealize Operations=8.6.0-hotfix8
VMware vRealize Operations=8.6.0-hotfix9
VMware vRealize Operations=8.10.0
VMware vRealize Operations=8.10.0-hotfix1
VMware vRealize Operations=8.10.0-hotfix2
Event History
May 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-20879?
CVE-2023-20879 is a local privilege escalation vulnerability in VMware Aria Operations.
2
What is the severity of CVE-2023-20879?
CVE-2023-20879 has a severity score of 6.7, which is considered medium.
3
How does CVE-2023-20879 affect VMware Cloud Foundation?
VMware Cloud Foundation is affected by CVE-2023-20879 if it is between versions 4.0 and 4.5.
4
How does CVE-2023-20879 affect VMware vRealize Operations 8.6.0?
VMware vRealize Operations 8.6.0 is affected by CVE-2023-20879.
5
How can I fix CVE-2023-20879?
To fix CVE-2023-20879, users should apply the necessary patches or updates provided by VMware.