Database/Kernel, userspace & hypervisor
VMware Tools: A fully compromised ESXi host can force VMware Tools to skip host-to-guest authentication
CVE-2023-20867Kernel, userspace & hypervisorKnown exploitedcurated
Impact
A fully compromised ESXi host can force VMware Tools to skip host-to-guest authentication - used by UNC3886 for stealthy guest access [KEV]
Who can reach it
Compromised hypervisor against tenant guests
What to do
VMware Tools update inside every guest image - tenant-side action a neocloud can only mandate, not perform. Low CVSS, high real-world significance for post-escape persistence
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.