ZeroHour

CVE-2023-20867

KEVmass1

Authentication Bypass in VMware Tools Lets Compromised ESXi Hosts Run Guest Operations

CISA: VMware Tools Authentication Bypass Vulnerability

CVSS 3.1
3.9 low
EPSS
14%p96
Published
()
KEV added
AI analysis

VMware Tools, the agent installed inside guest virtual machines, fails to properly authenticate host-to-guest operations when they are issued from an ESXi host (CVE-2023-20867, CWE-287 improper authentication). An attacker who has already gained full (root) control of an ESXi host can invoke these operations, such as running commands or moving files inside guest VMs, and the guests' VMware Tools will accept them without valid authentication. This gives an attacker a foothold in guest VMs without guest credentials, affecting guest confidentiality and integrity. Any organization running VMware ESXi/vSphere with VMware Tools in its guests is affected, and the component is also shipped as open-vm-tools in Debian and Fedora. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-23 (EPSS 13.5%, 96th percentile), and China-linked APT UNC3886, whose 'Fire Ant' tooling targets ESXi and vCenter, has been reported using it alongside other VMware flaws.

What to do: Upgrade VMware Tools / open-vm-tools to the latest fixed release distributed by VMware, Debian, or Fedora per the vendor advisory, and inventory guests running outdated Tools. Because exploitation requires a fully compromised ESXi host, hunt for signs of host compromise (unexpected processes, modified VIBs, suspicious vCenter activity) and review guest VMs for unexplained command execution or persistence. Consistent with the KEV required action, prioritize patching, starting with internet-facing ESXi hosts and virtualization management infrastructure.

Affected
VMware Tools
Debian Linux (open-vm-tools package)
Fedora Project Fedora (open-vm-tools package)
Estimated exposure
mass≈millions of guest VMs (VMware Tools is installed by default on nearly all VMware guests), though actual exploitability requires an already fully compromised… — VMware Tools ships with and is installed by default on essentially every guest VM on VMware ESXi/Workstation/Fusion, and the VMware virtualization installed base runs to millions of VMs, so the order-of-magnitude exposed population is in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.

CISA Known Exploited Vulnerability
Affected
VMware Tools
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
vmwaredebianfedoraproject
Products
tools, debian linux, fedora
Weakness
CWE-287
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

In the news