HomeSecurityPoC released for critical vulnerability in VMware Workstation

PoC released for critical vulnerability in VMware Workstation

A proof-of-concept (PoC) exploit has been released for a critical chain of vulnerabilities in VMware Workstation that allows an attacker to escape from a guest virtual machine and execute arbitrary code on the host operating system.

See also: Chinese hackers exploit VMware zero-day since October 2024

VMware Workstation
PoC released for critical vulnerability in VMware Workstation

The exploit successfully combines an information leak and a stack buffer overflow vulnerability to achieve complete guest-to-host escape, one of the most serious forms of security flaws in virtualization software.

The exploit targets vulnerabilities first presented at the Pwn2Own Vancouver event in 2023. Security researcher Alexander Zaviyalov of NCC Group recently published a detailed technical analysis and a working PoC, demonstrating the practical risk posed by these vulnerabilities.

The guest-to-host escape is achieved by chaining two distinct vulnerabilities found in VMware Workstation's Bluetooth virtual device functionality. This feature, which is enabled by default, allows a guest VM to use the host's Bluetooth adapter.

The first stage of the attack exploits a Use-After-Free (UAF) memory leak. By sending specially crafted USB Request Block (URB) to the virtual mouse and Bluetooth devices, an attacker can leak memory pointers from the vmware-vmx.exe to the host. This information leak is critical for bypassing Address Space Layout Randomization (ASLR), a standard security feature that randomizes memory locations to make it more difficult to exploit.

See also: Critical vulnerabilities in VMware vCenter and NSX

PoC released for critical vulnerability in VMware Workstation
PoC released for critical vulnerability in VMware Workstation

With ASLR bypassed, the attacker moves on to the second stage. This involves triggering a buffer overflow in the stack by sending a malicious Service Discovery Protocol (SDP) packet from the guest VM to another Bluetooth device that is discoverable by the host. The overflow allows the attacker to capture the flow of program execution and, with the previously leaked memory addresses, can execute a custom payload on the host system.

The combination of these vulnerabilities allows an attacker with control of a guest VM to gain complete control of the host machine. In the demonstration, the exploit successfully launched a reverse shell from a Linux guest to a fully updated Windows 11 host, effectively compromising the underlying system, Alexander Zaviyalov said.

The full exploit chain primarily affects VMware Workstation 17.0.1 and earlier versions. The specific vulnerabilities have different patch schedules: The stack buffer overflow (CVE-2023-20869) was addressed in version 17.0.2. The memory leak vulnerabilities (CVE-2023-20870 and CVE-2023-34044) were fixed in versions 17.0.2 and 17.5.0, respectively.

See also: Zero-day vulnerability exploit in VMware Tools and Aria

PoC released for critical vulnerability in VMware Workstation

For users who are unable to update immediately, a possible solution is to disable the virtual Bluetooth device. This can be done by deselecting the “Share Bluetooth devices with the virtual machine” option in the virtual machine’s USB controller settings.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS