First published: Tue Sep 26 2023(Updated: )
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vRealize Operations | =8.6.0 | |
VMware vRealize Operations | =8.10.0 | |
VMware vRealize Operations | =8.12.0 | |
VMware vRealize Operations | =8.12.0-hotfix1 | |
VMware vRealize Operations | =8.12.0-hotfix2 | |
VMware vRealize Operations | =8.12.0-hotfix3 | |
VMware vCenter Server and Cloud Foundation | >=4.0<4.4 | |
VMware vCenter Server and Cloud Foundation | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-34043.
The severity of the CVE-2023-34043 vulnerability is medium.
Versions 8.6.0, 8.10.0, 8.12.0, 8.12.0-hotfix1, 8.12.0-hotfix2, and 8.12.0-hotfix3 of VMware Aria Operations are affected by CVE-2023-34043.
A malicious actor with administrative access to the local system can escalate privileges to 'root' using CVE-2023-34043.
You can find more information about CVE-2023-34043 at the following link: https://www.vmware.com/security/advisories/VMSA-2023-0020.html