CVE-2023-20880: Medium severity vmware vrealize operations vulnerability
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20880?
CVE-2023-20880 is a privilege escalation vulnerability in VMware Aria Operations, allowing a malicious actor to escalate privileges to 'root' on a system with administrative access.
How severe is CVE-2023-20880?
CVE-2023-20880 has a severity rating of 6.7, which is considered medium.
Which software is affected by CVE-2023-20880?
VMware Aria Operations versions 8.6.0 to 8.12.0 and VMware Cloud Foundation versions 4.0 to 4.5 are affected by CVE-2023-20880.
How can an attacker exploit CVE-2023-20880?
An attacker with administrative access to the local system can exploit CVE-2023-20880 to escalate privileges to 'root'.
Is there a fix available for CVE-2023-20880?
Yes, VMware has released a security advisory (VMSA-2023-0009) providing information on how to fix CVE-2023-20880. Please refer to the advisory for specific mitigation steps.