CVE-2023-34044

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
20/10/2023
Last modified:
28/10/2023

Description

VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds <br /> read vulnerability that exists in the functionality for sharing host <br /> Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual <br /> machine may be able to read privileged information contained in <br /> hypervisor memory from a virtual machine.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* 17.0.0 (including) 17.5 (excluding)
cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* 13.0.0 (including) 13.5 (excluding)
cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools