VMware has released patches for a security vulnerability in its Workstation software, which could be used by malicious hackers to gain elevated privileges. This flaw, known as CVE-2023-20854 and rated as high severity, allows a local user to delete arbitrary files from the system on which Workstation is installed. The vulnerability was reported by Frederik Reiter of Cirosec, who also mentioned on Twitter that it can be used to escalate privileges to System. Cirosec will provide more technical details in the near future. Although this vulnerability has not been exploited yet, VMware users should be aware of the recently patched vRealize Log Insight flaws, for which exploit code is available. The cybersecurity industry is monitoring any attempts to exploit these vulnerabilities.
This Cyber News was published on www.securityweek.com. Publication date: Fri, 03 Feb 2023 16:55:03 +0000