December 1, 2023

VMware has fixed a high-severity privilege escalation flaw, tracked as CVE-2023-20854 with a CVSS score of 7.8, that impacts Workstation.

An attacker can exploit the vulnerability to delete arbitrary files on Workstation version 17.x for Windows OS.

An arbitrary file deletion vulnerability in VMware Workstation was privately reported to VMware. Updates are available to remediate this vulnerability in the affected VMware product.

Researchers plan to release technical details soon. in the meantime, it urges customers to patch their systems. The security firm says this flaw allows local privilege escalation to SYSTEM.

This research was documented by researchers from Cirosec GmbH.

Leave a Reply

%d bloggers like this: