First published: Fri May 12 2023(Updated: )
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Aria Operations | >=8.6.0<8.12.0 | |
VMware Cloud Foundation | >=4.0<=4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20880 is a privilege escalation vulnerability in VMware Aria Operations, allowing a malicious actor to escalate privileges to 'root' on a system with administrative access.
CVE-2023-20880 has a severity rating of 6.7, which is considered medium.
VMware Aria Operations versions 8.6.0 to 8.12.0 and VMware Cloud Foundation versions 4.0 to 4.5 are affected by CVE-2023-20880.
An attacker with administrative access to the local system can exploit CVE-2023-20880 to escalate privileges to 'root'.
Yes, VMware has released a security advisory (VMSA-2023-0009) providing information on how to fix CVE-2023-20880. Please refer to the advisory for specific mitigation steps.