Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-34059


open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.


Published

2023-10-27T05:15:39.013

Last Modified

2025-03-06T16:15:42.033

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-404

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application vmware open_vm_tools ≤ 12.3.0 Yes
Operating System debian debian_linux 10.0 Yes
Operating System debian debian_linux 11.0 Yes
Operating System debian debian_linux 12.0 Yes

References