Database/Kernel, userspace & hypervisor
VMware Tools: A fully compromised ESXi host can force VMware Tools to skip host-to-guest authentication
CVSS 3.9CVE-2023-20867Kernel, userspace & hypervisorKnown exploitedcurated
Impact
A fully compromised ESXi host can force VMware Tools to skip host-to-guest authentication - used by UNC3886 for stealthy guest access [KEV]
Who can reach it
Compromised hypervisor against tenant guests
What to do
VMware Tools update inside every guest image - tenant-side action a neocloud can only mandate, not perform. Low CVSS, high real-world significance for post-escape persistence
References
Related entries
- OpenSSL: non-constant-time SM2 point multiplication on AArch64 and RISC-V leaks key bits via timing and cacheCVE-2026-54875 · OpenSSL (SM2 scalar multiplication on AArch64 and RISC-V)Low
- OpenSSH: heap out-of-bounds read during GSSAPI indicator cleanup crashes the authentication pathCVE-2026-55654 · OpenSSH sshd (GSSAPI auth-indicator cleanup)Low
- strongSwan: PKCS#7 certificate enumeration in the openssl plugin leaks memoryCVE-2026-78124 · strongSwan openssl plugin (PKCS#7 certificate enumeration)Low
- OpenSSH ssh-agent: locking bypass lets a forwarded remote session add tokens and use keysCVE-2026-73281 · OpenSSH ssh-agent (agent locking vs session-bind@openssh.com extension)Low
- Linux kernel mlx5_ib (create QP response): mlx5_ib_create_qp_resp is never initialized in create_qp_common, so creatingCVE-2018-20855 · Linux kernel mlx5_ib (create QP response)Low
- Xen on AMD Family 17h / Hygon Family 18h - guest SSBD selection: Setting Speculative Store Bypass Disable on AMD FamilyCVE-2022-42336 · Xen on AMD Family 17h / Hygon Family 18h - guest SSBD selectionLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.