GPU VulnDB

Database/Kernel, userspace & hypervisor

VMware Tools: A fully compromised ESXi host can force VMware Tools to skip host-to-guest authentication

CVE-2023-20867Kernel, userspace & hypervisorKnown exploitedcurated

Impact

A fully compromised ESXi host can force VMware Tools to skip host-to-guest authentication - used by UNC3886 for stealthy guest access [KEV]

Who can reach it

Compromised hypervisor against tenant guests

What to do

VMware Tools update inside every guest image - tenant-side action a neocloud can only mandate, not perform. Low CVSS, high real-world significance for post-escape persistence

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.