nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-34044 CVE-2023-34044
HIGH
Information disclosure vulnerability in bluetooth device-sharing functionality
Record summary
CVE-2023-34044 has a selected CVSS score of 7.1 (high).
Description
VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
FusionBrowse VMware / FusionDefault status: unaffected | CVE List | 13.x to < 13.5 | affected |
WorkstationBrowse VMware / WorkstationDefault status: unaffected | CVE List | 17.x to < 17.5 | affected |
References
2vmware.com
https://www.vmware.com/security/advisories/VMSA-2023-0022.html