Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2023-20869] Chaining N-days to Compromise All: Part 5 — VMware Workstation Guest-to-Host Escape

theori.io | vulnerability | CVE-2023-20869 | #vmware | #bluetooth | #pwn2own | #cve-2023-20869 | #guest-to-host

Summary

Part five of the chain: how CVE-2023-20869 in VMware Workstation’s virtual Bluetooth SDP handling lets a guest execute arbitrary code on the host, with root-cause analysis and a working PoC.
Published
Collected

original ↗

Related coverage

back