USN-6257-1: Open VM Tools vulnerability
27 July 2023
open-vm-tools could be made to bypass authentication.
Releases
Packages
- open-vm-tools - Open VMware Tools for virtual machines hosted on VMware
Details
It was discovered that Open VM Tools incorrectly handled certain
authentication requests. A fully compromised ESXi host can force Open VM
Tools to fail to authenticate host-to-guest operations, impacting the
confidentiality and integrity of the guest virtual machine. (CVE-2023-20867)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 23.04
Ubuntu 22.04
Ubuntu 20.04
Ubuntu 18.04
-
open-vm-tools
-
2:11.0.5-4ubuntu0.18.04.3+esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
open-vm-tools
-
2:10.2.0-3~ubuntu0.16.04.1+esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.