Skip to content

open-vm-tools CVE-2023-20900

High
arnaldo2792 published GHSA-q879-mrf6-4fg3 Oct 10, 2023

Package

open-vm-tools (bottlerocket)

Affected versions

< 1.15.1

Patched versions

1.15.1

Description

A malicious actor that has been granted Guest Operation Privileges in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias.

Severity

High

CVE ID

CVE-2023-20900

Weaknesses

No CWEs