CVE-2023-34044: High severity vmware workstation and esxi vulnerability
VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this VMware Workstation and Fusion vulnerability?
The vulnerability ID for this VMware Workstation and Fusion vulnerability is CVE-2023-34044.
What is the severity of CVE-2023-34044?
The severity of CVE-2023-34044 is high with a severity value of 7.1.
Which software versions are affected by CVE-2023-34044?
VMware Workstation versions prior to 17.5 and Fusion versions prior to 13.5 are affected by CVE-2023-34044.
What is the risk of CVE-2023-34044?
The risk of CVE-2023-34044 is an out-of-bounds read vulnerability that allows a malicious actor with local administrative privileges on a virtual machine to potentially exploit the vulnerability.
Is Apple Mac OS X affected by CVE-2023-34044?
No, Apple Mac OS X is not vulnerable to CVE-2023-34044.