Threat Advisory

VMware fixes critical zero-day exploit chain used at Pwn2Own

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

VMware has made security updates available to fix zero-day flaws that might be coupled to allow code execution on systems running out-of-date versions of the company's Workstation and Fusion software hypervisors. Researchers discovered the two flaws one month ago on the second day of the Pwn2Own Vancouver 2023 hacking competition. They were part of an exploit chain. Before Trend Micro's Zero Day Initiative publishes technical information, vendors have 90 days to fix the zero-day issues that were exploited and revealed during Pwn2Own.[/subscribe_to_unlock_form]

Summary:

VMware has made security updates available to fix zero-day flaws that might be coupled to allow code execution on systems running out-of-date versions of the company's Workstation and Fusion software hypervisors. Researchers discovered the two flaws one month ago on the second day of the Pwn2Own Vancouver 2023 hacking competition. They were part of an exploit chain. Before Trend Micro's Zero Day Initiative publishes technical information, vendors have 90 days to fix the zero-day issues that were exploited and revealed during Pwn2Own.[emaillocker id="1283"]

  • CVE-2023-20869: - The first vulnerability, identified is a stack-based buffer overflow flaw in the Bluetooth device sharing capability that enables local attackers to run code as the virtual machine's VMX process running on the host.
  • CVE-2023-20870: - The sharing of host Bluetooth devices with the VM has a vulnerability in information leakage that allows malicious actors to read privileged information from a VM's hypervisor memory. This is the second bug fixed today.
  • CVE-2023-20871: - A high-severity VMware Fusion Raw Disc local privilege escalation vulnerability that may be exploited by attackers having read/write access to the host operating system to escalate privileges and obtain root access to the host OS.
  • CVE-2023-20872: - The SCSI CD/DVD device emulation is affected by a fourth problem that is referred to as "an out-of-bounds read/write vulnerability" and affects both Workstation and Fusion products.

The goal is to get code execution on the hypervisor from a VM, local attackers can access VMs that have a physical CD/DVD drive attached and are set up to use a virtual SCSI controller. Admins must remove the CD/DVD device from the virtual machine or configure the virtual machine NOT to use a virtual SCSI controller in order to temporarily fix CVE-2023-20872 which prevents exploitation attempts.

Recommendations:

We strongly recommend that you upgrade to VMware Workstation version 17.0.2 and Fusion 13.0.2

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/vmware-fixes-critical-zero-day-exploit-chain-used-at-pwn2own/

[/emaillocker]
crossmenu