← Vulnerability feed

Vulnerability record · CVE-2023-20871 · published 25 April 2023

CVE-2023-20871: Vmware fusion incorrect authorization vulnerability

Vmware · Fusion

VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system.

7.8 CVSS 3.1 High EPSS 0.38% · top 70.1% CWE-863 · Incorrect authorization
7.8CVSS 3.1 base score
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-20871 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-3950VMware Fusion, VMRC and Horizon Client setuid privilege escalationVMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac mishandle setuid binaries, allowing a local user to gain root. The flaw affec…KEVEPSS 7.3%analysed6.0CVE-2025-22226VMware ESXi, Workstation and Fusion HGFS out-of-bounds read leaks vmx memoryVMware ESXi, Workstation, Fusion and related cloud products contain an out-of-bounds read in the HGFS (Host Guest File System) component. A malicious…KEVEPSS 1.8%analysed9.9CVE-2017-4901Vmware fusion memory buffer overflow vulnerabilityThe drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory acc…EPSS 20%9.6CVE-2019-5521Vmware fusion out-of-bounds read vulnerabilityVMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6) and Fusion (1…EPSS 1.6%9.3CVE-2012-3288Vmware workstation improper input validation vulnerabilityVMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x before 4.1.3, VMware…EPSS 3.8%9.3CVE-2011-3868Vmware workstation memory buffer overflow vulnerabilityBuffer overflow in VMware Workstation 7.x before 7.1.5, VMware Player 3.x before 3.1.5, VMware Fusion 3.1.x before 3.1.3, and VMware AMS allows remot…EPSS 5.8%9.1CVE-2019-5541Vmware workstation out-of-bounds write vulnerabilityVMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network ad…EPSS 1.4%9.0CVE-2012-2449Vmware workstation memory buffer overflow vulnerabilityVMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2023-20871), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.