CVE Vulnerabilities

CVE-2023-20854

Improper Privilege Management

Published: Feb 03, 2023 | Modified: Feb 15, 2023
CVSS 3.x
8.4
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victims machine may exploit this vulnerability to delete arbitrary files from the file system of the machine on which Workstation is installed.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Workstation Vmware 17.0 (including) 17.0 (including)

Potential Mitigations

References