CVE-2023-34046

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/10/2023
Last modified:
07/03/2025

Description

VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) <br /> vulnerability that occurs during installation for the first time (the <br /> user needs to drag or copy the application to a folder from the &amp;#39;.dmg&amp;#39; <br /> volume) or when installing an upgrade. A malicious actor with local non-administrative user privileges may <br /> exploit this vulnerability to escalate privileges to root on the system <br /> where Fusion is installed or being installed for the first time.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* 13.0.0 (including) 13.5 (excluding)
cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*