CVE-2023-34044

Published Oct 20, 2023

Last updated 2 years ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2023-34044 is an out-of-bounds read vulnerability found in VMware Workstation (versions 17.x prior to 17.5) and Fusion (versions 13.x prior to 13.5). It exists in the functionality that shares host Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual machine could exploit this vulnerability to read privileged information contained in hypervisor memory from a virtual machine. The vulnerability is due to improper initialization of memory prior to accessing it within the UHCI component.

Description
VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.
Source
security@vmware.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
6
Impact score
4
Exploitability score
1.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

nvd@nist.gov
CWE-125

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.