CVE-2023-20870
NixOS vulnerability analysis and mitigation

Overview

VMware Workstation and Fusion contain an out-of-bounds read vulnerability (CVE-2023-20870) that exists in the functionality for sharing host Bluetooth devices with the virtual machine. The vulnerability was discovered by STAR Labs researchers during the Pwn2Own 2023 hacking contest in Vancouver and was publicly disclosed in April 2023. The affected products include VMware Workstation Pro v17.x and VMware Fusion v13.x (VMware Advisory).

Technical details

The vulnerability is classified as an out-of-bounds read vulnerability with a CVSS v3.1 base score of 6.0 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N). The specific flaw exists within the UHCI component and results from the lack of proper initialization of memory prior to accessing it (ZDI Advisory).

Impact

A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine. The vulnerability can be leveraged in conjunction with other vulnerabilities to execute arbitrary code in the context of the hypervisor (VMware Advisory, ZDI Advisory).

Exploitability

The vulnerability was successfully exploited by STAR Labs researchers during the Pwn2Own 2023 contest in March 2023, where it was chained with another vulnerability (CVE-2023-20869) to achieve code execution. The exploit earned the researchers $80,000 in prize money (Bleeping Computer).

Mitigation and workarounds

VMware has released security updates to address this vulnerability. Users should update to VMware Workstation Pro 17.0.2 or VMware Fusion 13.0.2. As a temporary workaround, administrators can turn off Bluetooth support on the virtual machine by unchecking the 'Share Bluetooth devices with the virtual machine' option (VMware Advisory).

Community reactions

The vulnerability was part of a significant security update that addressed multiple vulnerabilities in VMware's virtualization software. The successful exploitation during Pwn2Own 2023 contributed to pushing the contest's total prize money past $1,000,000 (Bleeping Computer).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management