VMware Security Updates – 29 October 2023

VMware has released security updates to address vulnerabilities affecting VMware Tools version 12.x.x, 11.x.x, 10.3.x macOS and Windows.

The addressed vulnerabilities could allow the attacker to gain elevated privileges on the affected systems.

Sample of the addressed vulnerabilities:

VMware Tools Privilege Escalation (CVE-2023-34057):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges
Vulnerabilities
  • CVE-2023-34057
  • CVE-2023-34058
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

VMware Security Advisory

References