VMware Security Update – 31 August 2023

VMware has released a security update to fix a vulnerability across multiple versions of VMware Tools.

The addressed vulnerability could allow the attacker with man-in-the-middle (MITM) network positioning between vCenter server and the virtual machine to bypass SAML token signature verification on the affected versions of VMware Tools.

SAML Token Signature Bypass Vulnerability (CVE-2023-20900):

  • CVSS: 7.5
  • Attack Vector: Adjacent
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Bypass Security
Vulnerabilities

CVE-2023-20900

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

VMware Security Advisory

References