Summary:
VMware has made security updates available to fix zero-day flaws that might be coupled to allow code execution on systems running out-of-date versions of the company's Workstation and Fusion software hypervisors. Researchers discovered the two flaws one month ago on the second day of the Pwn2Own Vancouver 2023 hacking competition. They were part of an exploit chain. Before Trend Micro's Zero Day Initiative publishes technical information, vendors have 90 days to fix the zero-day issues that were exploited and revealed during Pwn2Own.[/subscribe_to_unlock_form]
Summary:
VMware has made security updates available to fix zero-day flaws that might be coupled to allow code execution on systems running out-of-date versions of the company's Workstation and Fusion software hypervisors. Researchers discovered the two flaws one month ago on the second day of the Pwn2Own Vancouver 2023 hacking competition. They were part of an exploit chain. Before Trend Micro's Zero Day Initiative publishes technical information, vendors have 90 days to fix the zero-day issues that were exploited and revealed during Pwn2Own.[emaillocker id="1283"]
The goal is to get code execution on the hypervisor from a VM, local attackers can access VMs that have a physical CD/DVD drive attached and are set up to use a virtual SCSI controller. Admins must remove the CD/DVD device from the virtual machine or configure the virtual machine NOT to use a virtual SCSI controller in order to temporarily fix CVE-2023-20872 which prevents exploitation attempts.
Recommendations:
We strongly recommend that you upgrade to VMware Workstation version 17.0.2 and Fusion 13.0.2
References:
The following reports contain further technical details:
[/emaillocker]