CVE Vulnerabilities

CVE-2023-20854

Improper Privilege Management

Published: Feb 03, 2023 | Modified: Mar 26, 2025
CVSS 3.x
8.4
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victims machine may exploit this vulnerability to delete arbitrary files from the file system of the machine on which Workstation is installed.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
WorkstationVmware17.0 (including)17.0 (including)

Potential Mitigations

References