Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

VMware fixed critical guest-to-host vulnerability CVE-2023-20869 in Workstation 17.0.2 and Fusion 13.0.2. The flaw involved sharing host Bluetooth devices with a virtual machine: an attacker with local administrator privileges inside a guest could potentially execute code as the VMX process on the host. VMware rated it CVSS 9.3.

What was disclosed at Pwn2Own?

At Pwn2Own Vancouver 2023, STAR Labs researchers demonstrated CVE-2023-20869, a stack-based buffer overflow in VMware Workstation and Fusion’s host Bluetooth device-sharing functionality. VMware assigned the vulnerability a critical severity rating and CVSS score of 9.3. Reporting on the contest said STAR Labs received an $80,000 bounty for the finding.

The flaw matters because the virtual machine is not necessarily a security boundary when vulnerable device-sharing functionality is exposed. Successful exploitation could let code running in the guest execute as the VMX process on the host. This is a guest-to-host escape path, not simply a crash or an issue confined to the virtual machine.

What does an attacker need to exploit it?

For CVE-2023-20869, exploitation requires local administrative privileges inside the virtual machine. The vulnerability is specifically tied to sharing host Bluetooth devices with a guest; the disclosed impact is execution as the host-side VMX process. The CVE does not mean that any ordinary guest user can automatically take over a host, nor does the available advisory detail establish that Bluetooth must be actively in use at the moment of exploitation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Which VMware versions fix the vulnerabilities?

Product Affected branch identified in the update Fixed release
VMware Workstation 17.x 17.0.2
VMware Fusion 13.x 13.0.2

These are the key fixed releases identified for the affected branches in VMware’s April 2023 update. Check VMware/Broadcom’s current product channels and the applicable security advisory for your installation’s supported upgrade path and entitlement; do not assume these historical release numbers are the latest available versions today.

What other flaws were included in the update?

The same update addressed three additional CVEs. Their attack conditions and impacts differ from the Bluetooth stack overflow:

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • CVE-2023-20870: An out-of-bounds read in Bluetooth device sharing that could expose privileged hypervisor memory.
  • CVE-2023-20871: A local privilege-escalation issue in VMware Fusion.
  • CVE-2023-20872: An out-of-bounds read/write issue in SCSI CD/DVD emulation. It could allow code execution on the hypervisor from a VM when a physical CD/DVD drive is attached and configured with a virtual SCSI controller.

The device configuration matters for CVE-2023-20872: the stated scenario requires a physical optical drive attached to the virtual machine and configured to use a virtual SCSI controller. That condition is distinct from the Bluetooth-sharing condition in CVE-2023-20869.

What should VMware Workstation and Fusion users do?

  1. Inventory desktop hypervisors. Identify systems running VMware Workstation 17.x or Fusion 13.x, including machines used to run untrusted guest operating systems.
  2. Install the applicable fixed update. Upgrade Workstation to at least the identified fixed release, 17.0.2, or Fusion to 13.0.2, following the vendor’s supported update channel and any newer release guidance.
  3. Review virtual-machine device settings. Where not needed, disable host Bluetooth sharing and avoid attaching physical CD/DVD devices to untrusted VMs, particularly with a virtual SCSI controller.
  4. Prioritize exposed or untrusted guests. Treat a VM that accepts untrusted software or users as higher risk when it has host-device sharing or passthrough configured.

Disabling an unnecessary sharing feature reduces exposure, but it is not a substitute for applying the vendor patch. The fixes cover multiple vulnerabilities, and the issues do not all depend on the same device configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Security with Keys, Anti-Theft, Screw Styles
  • With strict control and, high factors, can be used with peace of mind
  • Works with most desktops, docking stations with built-in security locking slot hole
  • Fine workmans ship make sure they are perfect to use
  • Protect your computer and its valuable data with this computer
  • metal, multi-layer plating color, do not fade, long-life
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Was there confirmed exploitation in the wild?

The available reporting and advisory material reviewed for this article does not establish confirmed malicious in-the-wild exploitation of these specific CVEs after disclosure. That is not proof that exploitation was impossible or that no activity occurred; it means the cited material does not confirm it. Patching remains the appropriate response because the contest demonstration showed a practical attack path and the vendor rated the primary flaw critical.

Quick Recap

Bestseller No. 3
Security with Keys, Anti-Theft, Screw Styles
Security with Keys, Anti-Theft, Screw Styles
With strict control and, high factors, can be used with peace of mind; Works with most desktops, docking stations with built-in security locking slot hole
$10.49
Bestseller No. 4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
For the driver download and user guide, please visit TrustKey Solutions Home support page.
$18.00
Rank #4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.