CVE-2023-20872
HIGHVMware Fusion and Workstation - Out-of-bounds Write in SCSI CD/DVD Device Emulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-20872. PoCs published by ze0r.
AI-analyzed exploit summary This is a proof-of-concept exploit for CVE-2023-20872, targeting a VMware ESXi vulnerability. The code appears to be a kernel module designed to interact with SCSI devices, potentially exploiting a flaw in the MPT (Message Passing Technology) SPI host driver.
Description
VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.
Exploits (1)
This is a proof-of-concept exploit for CVE-2023-20872, targeting a VMware ESXi vulnerability. The code appears to be a kernel module designed to interact with SCSI devices, potentially exploiting a flaw in the MPT (Message Passing Technology) SPI host driver.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H