Vulnerability Description
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Open Vm Tools | >= 11.0.0, <= 12.3.0 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2023/10/27/2Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/10/27/3Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/11/26/1
- http://www.openwall.com/lists/oss-security/2023/11/27/1
- https://lists.debian.org/debian-lts-announce/2023/11/msg00002.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://www.debian.org/security/2023/dsa-5543Third Party Advisory
- https://www.vmware.com/security/advisories/VMSA-2023-0024.htmlNot Applicable
- http://www.openwall.com/lists/oss-security/2023/10/27/2Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/10/27/3Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/11/26/1
- http://www.openwall.com/lists/oss-security/2023/11/27/1
- https://lists.debian.org/debian-lts-announce/2023/11/msg00002.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2023-34059?
CVE-2023-34059 is a vulnerability with a CVSS score of 7.4 (HIGH). open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowin...
How severe is CVE-2023-34059?
CVE-2023-34059 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-34059?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Open Vm Tools, Debian Debian Linux.