Published On: May 02, 2023 14:59
Advisory No: TZCERT/SA/2023/04/28
Source: VMware
Software Affected: VMware Workstation17.x and VMware Fusion 13.x
Advisory No: TZCERT/SA/2023/04/28
Date of First Release: 28th April 2023
Source: VMware
Software Affected: VMware Workstation17.x and VMware Fusion 13.x
Overview:
VMware has released patches to address a critical vulnerability affecting VMware Workstation and VMware Fusion. The vulnerability could allow an attacker to take control of affected system.
Description:
VMware Workstation and VMware Fusion are infected with a stack-based buffer-overflow vulnerability in the functionality for sharing host Bluetooth devices with the virtual machine. The vulnerability allows a malicious an actor with local privilege to execute code as virtual machine’s VMX process running on the host.
Impact:
Successful exploitation of this vulnerability may allow the attacker to control of the affected system.
Solution:
VMware has released patches for this vulnerability. Users and administrators are encouraged to apply necessary updates.
References:
A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.