ZDI-CAN-21512: ZDI-23-1589: VMware Workstation UHCI Uninitialized Variable Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of VMware Workstation. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.0. The following CVEs are assigned: CVE-2023-34044.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21512?
The severity of ZDI-CAN-21512 has been classified as high due to its potential to disclose sensitive information.
How do I fix ZDI-CAN-21512?
To fix ZDI-CAN-21512, ensure you update your VMware Workstation to the latest version where the vulnerability is patched.
Who is affected by ZDI-CAN-21512?
ZDI-CAN-21512 affects all installations of VMware Workstation that allow local attackers to execute high-privileged code.
What does ZDI-CAN-21512 exploit allow attackers to do?
ZDI-CAN-21512 allows attackers to disclose sensitive information on the affected systems after gaining high privileges.
How can I prevent ZDI-CAN-21512 from being exploited?
To prevent ZDI-CAN-21512 from being exploited, implement strict access controls and regularly update your VMware Workstation software.