REDHAT-BUG-2236542: High severity vmware tools vulnerability
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor with man-in-the-middle (MITM) network positioning between vCenter server and the virtual machine may be able to bypass SAML token signature verification, to perform VMware Tools Guest Operations.
References:
https://www.vmware.com/security/advisories/VMSA-2023-0019.html https://www.openwall.com/lists/oss-security/2023/08/31/1 https://github.com/vmware/open-vm-tools/blob/CVE-2023-20900.patch/CVE-2023-20900.patch
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2236542?
The severity of REDHAT-BUG-2236542 is considered high due to its potential impact on SAML token security.
How do I fix REDHAT-BUG-2236542?
To fix REDHAT-BUG-2236542, users should update VMware Tools to the latest patched version provided by VMware.
What systems are affected by REDHAT-BUG-2236542?
REDHAT-BUG-2236542 affects VMware Tools installed on virtual machines that communicate with a vCenter server.
What type of vulnerability is REDHAT-BUG-2236542?
REDHAT-BUG-2236542 is a SAML token signature bypass vulnerability.
Can exploitation of REDHAT-BUG-2236542 lead to unauthorized access?
Yes, exploitation of REDHAT-BUG-2236542 can allow a malicious actor to perform unauthorized guest operations on virtual machines.