VMware fixed a high-severity privilege escalation flaw, tracked as CVE-2023-20854, that impacts Workstation.
An attacker can exploit the vulnerability to delete arbitrary files on Workstation version 17.x for Windows OS.
“An arbitrary file deletion vulnerability in VMware Workstation was privately reported to VMware. Updates are available to remediate this vulnerability in the affected VMware product.” reads the advisory published by the virtualization giant.
The issue was reported by Frederik Reiter of Cirosec GmbH, it has been rated with a CVSSv3 base score of 7.8.
Cirosec plans to release technical details soon, meantime, it urges customers to patch their systems. The security firm explained in a Tweet that the arbitrary file deletion vulnerability (CVE-2023-20854) allows local privilege escalation to SYSTEM.
Recently another flaw in VMware vRealize Log Insight, tracked as CVE-2022-31706 (CVSS base 9.8/10), made the headlines after Horizon3 security researchers released proof-of-concept (PoC) code.
The PoC exploit code will trigger a series of flaws in vRealize Log to achieve remote code execution on vulnerable installs.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, privilege escalation)
Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…
A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…
A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…
Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…
Google says nation-state actors used Gemini AI for reconnaissance and attack support in cyber operations.…
This website uses cookies.