A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://www.vmware.com/security/advisories/VMSA-2023-0013.html | patch vendor advisory |
https://security.netapp.com/advisory/ntap-20230725-0001/ | third party advisory |
https://lists.debian.org/debian-lts-announce/2023/08/msg00020.html | third party advisory mailing list |
https://www.debian.org/security/2023/dsa-5493 | third party advisory mailing list |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZJM6HDRQYS74JA7YNKQBFH2XSZ52HEWH/ | release notes mailing list |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NVKQ6Y2JFJRWPFOZUOTFO3H27BK5GGOG/ | release notes mailing list |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TJNJMD67QIT6LXLKWSHFM47DCLRSMT6W/ | release notes mailing list |
http://www.openwall.com/lists/oss-security/2023/10/16/2 | patch mailing list |
http://www.openwall.com/lists/oss-security/2023/10/16/11 | patch mailing list |