VMware has released security updates to address zero-day vulnerabilities that could be linked to execute code on systems running outdated versions of the company's Workstation and Fusion software hypervisors.
See also: Nevada Ransomware: Targets Windows and VMware ESXi

The two flaws were part of an exploit chain presented by security researchers from the STAR Labs team a month ago, during the second day of the Pwn2Own Vancouver 2023 hacking competition.
Vendors have 90 days to patch the zero-day bugs exploited and disclosed during Pwn2Own before Trend Micro's Zero Day Initiative publishes technical details.
The first vulnerability (CVE-2023-20869) is a stack-based buffer-overflow vulnerability in the Bluetooth device sharing functionality , which allows local attackers to execute code as the VMX process of the virtual machine running on the host.
The second bug fixed today (CVE-2023-20870) is an information disclosure vulnerability in the VM-to-host Bluetooth device sharing functionality, which allows malicious actors to read privileged information contained in hypervisor memory from a VM.
See also: Royal Ransomware: Linux version targets VMware ESXi servers
VMware also shared a temporary workaround for administrators who cannot immediately deploy fixes for the two flaws to systems .
To remove the attack vendor, you can also disable Bluetooth support in the virtual machine by disabling the “Share Bluetooth devices with the virtual machine” option on the affected devices (more details on how to do this can be found here).
The company today addressed two additional security vulnerabilities, affecting VMware Workstation and Fusion hosted hypervisors.
CVE-2023-20871 is a high severity VMware Fusion Raw Disk local privilege escalation vulnerability, which can be exploited by attackers with read and write access to the operating system to escalate privileges and gain root access to the host OS.
A fourth flaw (codenamed CVE-2023-20872), described as an “out-of-bounds read/write vulnerability” in SCSI CD/DVD device emulation, affects both Workstation and Fusion products.
This can be exploited by local attackers with access to a VM with a physical CD/DVD drive attached and configured to use a virtual SCSI controller, allowing them to gain code execution in the hypervisor from the VM.
See also: VMware fixes vRealize bug that allows attackers to execute code as root
A temporary CVE-2023-20872 workaround that blocks exploitation attempts requires administrators to “remove the CD/DVD device from the virtual machine or configure the virtual machine to NOT use a virtual SCSI controller.”
Last week, VMware also patched a critical vulnerability in vRealize Log Insight that could allow unauthorized attackers to gain remote execution on vulnerable devices.
Information source: bleepingcomputer.com
