CVE-2023-34043: Medium severity vmware vrealize operations vulnerability
Published Sep 26, 2023
·Updated
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
Affected Software
8 affected components
VMware Aria Operations=8.6.0
VMware Aria Operations=8.10.0
VMware Aria Operations=8.12.0
VMware Aria Operations=8.12.0-hotfix1
VMware Aria Operations=8.12.0-hotfix2
VMware Aria Operations=8.12.0-hotfix3
VMware Cloud Foundation>=4.0<4.4
VMware Cloud Foundation=5.0
Remediation
Event History
Sep 26, 2023
CVE Published
via MITRE·05:14 PM
Data Sourced
via MITRE·05:14 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the local privilege escalation vulnerability in VMware Aria Operations?
The vulnerability ID is CVE-2023-34043.
2
What is the severity of the CVE-2023-34043 vulnerability?
The severity of the CVE-2023-34043 vulnerability is medium.
3
Which version of VMware Aria Operations is affected by CVE-2023-34043?
Versions 8.6.0, 8.10.0, 8.12.0, 8.12.0-hotfix1, 8.12.0-hotfix2, and 8.12.0-hotfix3 of VMware Aria Operations are affected by CVE-2023-34043.
4
How can a malicious actor exploit the CVE-2023-34043 vulnerability?
A malicious actor with administrative access to the local system can escalate privileges to 'root' using CVE-2023-34043.
5
Where can I find more information about CVE-2023-34043?
You can find more information about CVE-2023-34043 at the following link: https://www.vmware.com/security/advisories/VMSA-2023-0020.html