
Guest-to-host escape in VMware Workstation (CVE-2023-20870/CVE-2023-34044 and CVE-2023-20869) Guest-to-host VM escape in VMware Workstation, stack buffer overflow in Bluetooth sharing leads to code execution (CVE-2023-20870/CVE-2023-34044 and CVE-2023-20869) https://nccgroup.com/media/b2chcbti/vmware-workstation-guest-to-host-escape.pdf Credits Alexander Zaviyalov (@NCCGroupInfosec) #infosec
Post summary
NCCGroup released a report detailing guest-to-host escape vulnerabilities in VMware Workstation, including a stack buffer overflow via Bluetooth sharing, but no PoC, exploit, or patch information is provided.
