Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In June 2023, Mandiant reported that the China-linked espionage group it tracks as UNC3886 exploited CVE-2023-20867, a VMware Tools authentication bypass, during intrusions involving ESXi hosts. The flaw did not give attackers a way into an uncompromised ESXi host: they first needed root-level access to a fully compromised host. From there, they could run commands and transfer files to guest virtual machines without guest credentials.

What Mandiant reported

On June 13, 2023, Mandiant said UNC3886 had used CVE-2023-20867 as a zero-day. The vulnerability let an attacker who already controlled an ESXi host perform host-to-guest operations without authenticating to the guest. Those operations included executing commands and moving files between the host and virtual machines. Mandiant reported that commands issued this way did not produce an authentication log event on the guest VM. Mandiant’s incident analysis describes the observed activity.

The broader activity Mandiant described included malicious vSphere Installation Bundles (VIBs), credential harvesting associated with vCenter and connected ESXi hosts, and backdoors communicating over VMCI sockets. These are techniques observed in the reported activity, not evidence that every technique occurred at every victim or that every VMware environment was affected.

What CVE-2023-20867 did—and did not do

Broadcom’s advisory identifies CVE-2023-20867 as an authentication bypass in the vgauth module of VMware Tools. It says a fully compromised ESXi host could force VMware Tools to fail to authenticate host-to-guest operations, affecting the confidentiality and integrity of the guest VM. VMware rated it Low, with a CVSSv3 base score of 3.9, and specified that an attacker needed root access over ESXi. Read VMSA-2023-0013.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Glovary N150 Mini PC Firewall (N100 Upgrade), 6 x 2.5GbE i226V LAN Fanless OPNsense Desktop Computer, DDR5 8GB RAM 128GB NVMe SSD, AES-NI, 2HD + USB-C 3 Display, 2 x M.2 NVMe Slot
  • Powerful 12th Gen N150 Processor: Glovary Firewall Box Computer with Twin Lake 12th Gen N150 Processor, 4 Cores 4 Threads, 6M Cache, up to 3.6 GHz, TDP 6W. Supports OPNsense, Linux, Openwrt, etc
  • 6 x i226V 2.5GbE Lan: Firewall router with 6 x i226-V network card, 2.5x faster than common Gigabit Ethernet. Soft Router can monitor network data, improve network security, powerful and widely used
  • DDR5 RAM 2 x M.2 NVMe Slot: Micro firewall appliance with 1 x DDR5 SO-DIMM, 2 x M.2 2280 NVMe SSD slot, 1 x SATA 3.0 for 2.5" SSD/HDD (SATA 3.0 Cable Included)
  • UHD Graphics & Triple Display: Mini PC Firewall with 2HD+Type-C triple display interfaces support 4K@60Hz, N150 processor integrated UHD Graphics. Fanless design with aluminium alloy body, quiet running without noise. Supports 12V 4 Pin 80 x 10mm small fan (Package includes 4Pin fan cable)
  • Package Contents: 1 xGlovary firewall appliance, 1 xPower adapter, 1 xSATA 3.0 cable, 1 x4pin fan cable, 1 xVESA bracket. Rich interfaces: 6 x2.5G i226V-LAN, 2 xHD, 1 xType-C, 1 xUSB3.2, 4 xUSB2.0, 1 xTF Card slot supports data storage and system boot

The prerequisite changes how to interpret the headline. This was not a remote-code-execution flaw that independently broke into a clean ESXi server. It became useful after an attacker had already gained complete control of the hypervisor—for example, through stolen ESXi credentials, as Mandiant discussed. The bypass then helped the attacker operate inside guest VMs without needing their credentials.

What VMware’s June 2023 advisory fixed

VMSA-2023-0013 listed VMware Tools 12.2.5 as the fixed version for affected 12.x, 11.x, and 10.3.x lines, and 10.3.26 for the older Linux line. The advisory also documented a Windows upgrade issue when moving from 12.2.0 to 12.2.5 and recommended 12.2.6 for that case. These are the versions specified in the June 2023 advisory; they are historical remediation references, not a statement of the newest supported versions in October 2026.

Rank #2
Protectli Vault Pro VP6670-6 Port, Micro Appliance/Mini PC - Intel i7, 2X 10G SFP+ & 4X 2.5G Ports, DDR5 RAM, M.2 NVMe or SATA SSD Storage, AES-NI, Barebones
  • THE VAULT PRO (VP6670): Secure your network with a compact & quiet appliance. Comes with US-based Support & 30-day money back guarantee!
  • CPU: Intel i7-1255U 10 Core / 12 Thread (Turbo up to 4.7 GHz), Intel AES-NI hardware support
  • PORTS: 6 ports (2x 10G SFP+ & 4x 2.5G NICs), 1x USB 3.1 Type -A, 1x USB 3.2 Type-C, 3x USB 2.0 Type-A,1x RJ-45 COM, 1x USB Type C COM Port, 1x HDMI, 1x DP
  • COMPONENTS: Barebones (No SSD, no RAM)
  • COMPATIBILITY: No OS pre-installed. All hardware tested with various hypervisors (Proxmox, ESXi, XCP-ng etc.), firewall software (compatible with OPNsense, pfSense, VyOS etc.), and other popular open-source software solutions. Ships with AMI BIOS.

How to check your environment

  1. Inventory VMware Tools versions installed in guest VMs, including their operating systems and release branches.
  2. Compare each installed version with Broadcom’s current security advisories and product lifecycle information. Use the current supported release guidance applicable to your environment rather than assuming the 2023 fixed versions remain current.
  3. Plan upgrades using the applicable vendor instructions. If you are assessing the specific Windows path from 12.2.0 to 12.2.5, account for the advisory’s recommendation to use 12.2.6 instead.
  4. Separately assess ESXi and vCenter security. Updating guest Tools does not establish whether a host was previously compromised or remove other attacker access.

What defenders should review

Mandiant’s June 28, 2023 follow-up discusses detection, containment, and hardening across ESXi hosts and vCenter. Its recommended areas of attention include Guest Operations logging on hosts and guests, unusual use of the vpxuser account, and exposed VMCI socket ports. See Mandiant’s detection and hardening guidance.

  • Review available host-side and guest-side Guest Operations logs for activity that warrants investigation. The absence of a guest authentication event does not rule out host-initiated operations.
  • Investigate anomalous vpxuser activity in the context of normal administration and the associated vCenter and ESXi activity.
  • Review VMCI socket exposure and whether it is needed for the workloads and configurations in use.
  • If compromise is suspected, treat vCenter and ESXi as part of the response scope, and use an incident-response plan to contain and investigate them alongside guest VMs.

No single log source or check proves that an environment is clean or compromised. Correlate findings with the host, vCenter, and guest evidence available to your organization.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
UDPTCP Firewall, Intelligent Soft Routing Micro Appliance/Fanless Mini PC • Celeron N2840, 2 x RJ45(1000M), USB 3.0,HDMI,VGA, 4GB RAM 64GB mSATA SSD
  • 【◆Powerful Celeron N2840 Processor: N2840 Processor, 2 Cores 2 Threads, 1M Cache, Max Turbo Frequency 2.58 GHz, TDP 7.5 W. Compatible with OPNsense, Linux, Windows,ESXI, OpenWrt and other systems. Press "Delete" key to enter BIOS setup, supports Auto Power On, Wake On Lake, GPIO, PXE
  • 【◆1GbE LAN: Mini Router PC with 2*Realtek RTL8111H network card chip full UDE 1000M with filter connector.Soft Router can monitor network data, improve network security, powerful and widely used.
  • ◆DDR3L Memory & Large Storage Capacity: Firewall box computer with 1 x DDR3L SO-DIMM memory 1333/1600MHz, 1xMSATA3.0 SSD+1x2.5''SATA3.0 SSD/HDD.
  • ◆UHD Graphics & Dual Display: N2840 processor integrated UHD Graphics, HD and VGA dual display interfaces support 4K@60Hz.
  • ◆Rich interfaces: 2 x1000M Realtek RTL8111H-LAN,2 xUSB3.0, 4 xUSB2.0, HDMI,VGA,AUDIO supports data storage and system boot.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the incident still matters to VMware administrators

CVE-2023-20867 is a useful example of how hypervisor compromise can undermine assumptions about guest boundaries: a guest’s own credentials were not required for the reported host-to-guest operations. The practical response is therefore twofold—keep VMware Tools within currently supported, remediated versions, and protect and investigate the management and hypervisor layer that can reach guest operations.

Best Value
Wantolan R1 Optical Firewall Mini PC,Alder Lake N100/i3-N305,Dual 10G Optical Ports,Dual 2.5G RJ45 Ports,Four Network Ports,DDR5 RAM,M.2 NVMe SSD,Dual HDMI2.0 (CPU/N150, RAM16GB/SSD256GB)
  • CPU:intel 12th gen. Alder Lake-N:N100/i3-N305.TDP of N100 is 6W and i3-N305 for 15W. N100 has 4 cores and 4 threads, with a clockspeed of 0.8GHz and a turbo speed up to 3.4GHz; i3-N305 has 8 cores and 8 threads, with a clockspeed of 1.8GHz and a turbo speed up to 3.8GHz. Meanwhile, the GPU models of these two CPUs are both intel UHD Graphics. X86 architecture, compatible with systems or software such as Win10,win11,Windows Server, Debian, Ubuntu,ESXi, PVE, OpenWRT, MikroTik, pfSense, OPNsense, Unraid, OMV, etc.
  • Network Interface: Dual 10G optical ports+Dual 2.5G electrical ports. The optical ports are SFP+, using intel 82599ES chip, compatible with 10G/1G. The electrical ports are RJ45, using intel i226-V chip. The combination of four network ports can be applied to intelligent routing or firewall. Optical ports can facilitate the construction of faster LAN or directly connect optical fibers through optical modules.
  • RAM/SSD: RAM uses a single SO-DIMM laptop memory slot, supports DDR5-4800MHz, and is compatible with DDR5-5600MHz. The SSD adopts a single M.2 PCIe 3.0 * 1 M-Key slot, supporting NVMe 2280 PCIe 3.0 * 4 SSD and compatible with PCIe 4.0 * 4 SSD. Installing SSD in this slot requires disassembling the motherboard. There is a WiFi E-Key slot on the other side of the motherboard that can be expanded. We will also give away a PCB adapter board. You can use it to convert E-Key slot into M-Key slot to expand an M.2 SSD. At the same time, a 4pin SATA socket is reserved on the motherboard, which can be expanded to accommodate a 2.5-inch SSD.
  • Radiation Design: The chassis is made of aluminum alloy and equipped with 2 copper heat sinks, one for CPU and one for 10G optical chip. During use, heat can be dissipated through the shell's heat sink fins. In addition, a 12V6010 PWM fan is installed by default under the top fan cover. Variable speed operation during use to assist in heat dissipation of the shell. This two in one design scheme effectively balances heat dissipation and noise reduction.There is also a 4Pin PWM system fan socket on the motherboard, which can be expanded with a 12V8010 fan.
  • Size/Weight: This is a relatively small 10G firewall mini PC. The size of R1 is about 5.83 inch(length)*5inch(width)*2.36inch(height).The net weight of R1 is approximately 1.1Kg.
Rank #4
Dell High-End PowerEdge R710 Server 2x 2.93Ghz X5670 6C 144GB 6x 2TB (Renewed)
  • This Certified Refurbished product is tested and certified to look and work like new. The refurbishing process includes functionality testing, basic cleaning, inspection, and repackaging. The product ships with all relevant accessories, a minimum 90-day warranty, and may arrive in a generic box. Only select sellers who maintain a high performance bar may offer Certified Refurbished products on Amazon.com
  • Dell PowerEdge R710 6B LFF Server
  • 2x 2.93GHz X5670 12-Cores Total / 144GB RAM / 6x 2TB 3.5" HDD
  • H700 w/ 512MB / DVD-ROM / 2x PSU
  • Includes Bezel and Rails / No Operating System

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.