CVE & CISA-KEV Catalog

CVE-2023-20900

HIGH
7.1
CVSS v3
NVD

Description

A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .

How to fix

Remediation Available
open-vm-toolsAmazon
Fixed in:0:12.3.0-1.amzn2
Fixed in:0:12.3.0-1.amzn2
Fixed in:0:12.3.0-1.amzn2023
Fixed in:0:12.3.0-1.amzn2023
open-vm-tools-debuginfoAmazon
Fixed in:0:12.3.0-1.amzn2
Fixed in:0:12.3.0-1.amzn2
Fixed in:0:12.3.0-1.amzn2023
Fixed in:0:12.3.0-1.amzn2023
open-vm-tools-debugsourceAmazon
Fixed in:0:12.3.0-1.amzn2023
Fixed in:0:12.3.0-1.amzn2023
open-vm-tools-desktopAmazon
Fixed in:0:12.3.0-1.amzn2
Fixed in:0:12.3.0-1.amzn2
Fixed in:0:12.3.0-1.amzn2023
Fixed in:0:12.3.0-1.amzn2023
open-vm-tools-desktop-debuginfoAmazon
Fixed in:0:12.3.0-1.amzn2023
Fixed in:0:12.3.0-1.amzn2023
open-vm-tools-develAmazon
Fixed in:0:12.3.0-1.amzn2
Fixed in:0:12.3.0-1.amzn2
Fixed in:0:12.3.0-1.amzn2023
Fixed in:0:12.3.0-1.amzn2023
open-vm-tools-salt-minionAmazon
Fixed in:0:12.3.0-1.amzn2
Fixed in:0:12.3.0-1.amzn2023
open-vm-tools-sdmpAmazon
Fixed in:0:12.3.0-1.amzn2
Fixed in:0:12.3.0-1.amzn2
Fixed in:0:12.3.0-1.amzn2023
Fixed in:0:12.3.0-1.amzn2023
open-vm-tools-sdmp-debuginfoAmazon
Fixed in:0:12.3.0-1.amzn2023
Fixed in:0:12.3.0-1.amzn2023
open-vm-tools-testAmazon
Fixed in:0:12.3.0-1.amzn2
Fixed in:0:12.3.0-1.amzn2
Fixed in:0:12.3.0-1.amzn2023
Fixed in:0:12.3.0-1.amzn2023
open-vm-tools-test-debuginfoAmazon
Fixed in:0:12.3.0-1.amzn2023
Fixed in:0:12.3.0-1.amzn2023
open-vm-toolsDebian
Fixed in:2:12.2.0-1+deb12u1CVE-2023-20900
Fixed in:2:12.3.0-1CVE-2023-20900
Fixed in:2:12.3.0-1CVE-2023-20900
open-vm-toolsRed Hat / RHEL
Fixed in:0:10.3.0-2.el7_7.3RHSA-2024:5315

This Red Hat / RHEL release reached end-of-life on 2024-06-30. Extended security maintenance is available until 2029-05-31.

Fixed in:0:11.0.5-3.el7_9.7RHSA-2023:5217

This Red Hat / RHEL release reached end-of-life on 2024-06-30. Extended security maintenance is available until 2029-05-31.

Fixed in:0:11.0.5-3.el7_9.7RHSA-2023:5217

This Red Hat / RHEL release reached end-of-life on 2024-06-30. Extended security maintenance is available until 2029-05-31.

Fixed in:0:10.3.0-2.el7_7.3RHSA-2024:5315

This Red Hat / RHEL release reached end-of-life on 2024-06-30. Extended security maintenance is available until 2029-05-31.

Fixed in:0:11.0.0-4.el8_2.3RHSA-2023:5210
Fixed in:0:11.3.5-1.el8_6.4RHSA-2023:5220
Fixed in:0:11.3.5-1.el8_6.4RHSA-2023:5220
Fixed in:0:12.1.5-2.el8_8.3RHSA-2023:5312
open-vm-toolsRocky
Fixed in:0:10.3.0-2.el7_7.3RHSA-2024:5315
Fixed in:0:10.3.0-2.el7_7.3RHSA-2024:5315
Fixed in:0:11.0.5-3.el7_9.7RHSA-2023:5217
Fixed in:0:11.0.5-3.el7_9.7RHSA-2023:5217
Fixed in:0:11.2.0-2.el8_4.3RHSA-2023:5216
Fixed in:0:11.2.0-2.el8_4.3RHSA-2023:5216
Fixed in:0:11.3.5-1.el8_6.4RHSA-2023:5220
Fixed in:0:11.3.5-1.el8_6.4RHSA-2023:5220
open-vm-tools-debuginfoRed Hat / RHEL
Fixed in:0:10.3.0-2.el7_7.3RHSA-2024:5315

This Red Hat / RHEL release reached end-of-life on 2024-06-30. Extended security maintenance is available until 2029-05-31.

Fixed in:0:11.0.5-3.el7_9.7RHSA-2023:5217

This Red Hat / RHEL release reached end-of-life on 2024-06-30. Extended security maintenance is available until 2029-05-31.

Fixed in:0:10.3.10-3.el8_1.4RHSA-2023:5213
Fixed in:0:12.1.5-2.el8_8.3RHSA-2023:5312
Fixed in:0:11.2.0-2.el8_4.3RHSA-2023:5216
Fixed in:0:11.0.0-4.el8_2.3RHSA-2023:5210
Fixed in:0:11.3.5-1.el8_6.4RHSA-2023:5220
Fixed in:0:12.1.5-1.el9_2.3RHSA-2023:5313
open-vm-tools-debuginfoRocky
Fixed in:0:11.0.5-3.el7_9.7RHSA-2023:5217
Fixed in:0:10.3.0-2.el7_7.3RHSA-2024:5315
Fixed in:0:11.0.0-4.el8_2.3RHSA-2023:5210
Fixed in:0:12.1.5-2.el8_8.3RHSA-2023:5312
Fixed in:0:11.3.5-1.el8_6.4RHSA-2023:5220
Fixed in:0:10.3.10-3.el8_1.4RHSA-2023:5213
Fixed in:0:11.2.0-2.el8_4.3RHSA-2023:5216
Fixed in:0:11.3.5-1.el9_0.4RHSA-2023:5218
open-vm-tools-debugsourceRed Hat / RHEL
Fixed in:0:11.0.0-4.el8_2.3RHSA-2023:5210
Fixed in:0:12.1.5-2.el8_8.3RHSA-2023:5312
Fixed in:0:10.3.10-3.el8_1.4RHSA-2023:5213
Fixed in:0:11.3.5-1.el8_6.4RHSA-2023:5220
Fixed in:0:11.2.0-2.el8_4.3RHSA-2023:5216
Fixed in:0:11.3.5-1.el9_0.4RHSA-2023:5218
Fixed in:0:12.1.5-1.el9_2.3RHSA-2023:5313
Fixed in:0:12.1.5-1.el9_2.3RHSA-2023:5313
open-vm-tools-debugsourceRocky
Fixed in:0:11.0.0-4.el8_2.3RHSA-2023:5210
Fixed in:0:12.1.5-2.el8_8.3RHSA-2023:5312
Fixed in:0:10.3.10-3.el8_1.4RHSA-2023:5213
Fixed in:0:11.2.0-2.el8_4.3RHSA-2023:5216
Fixed in:0:11.3.5-1.el8_6.4RHSA-2023:5220
Fixed in:0:11.3.5-1.el9_0.4RHSA-2023:5218
Fixed in:0:11.3.5-1.el9_0.4RHSA-2023:5218
Fixed in:0:12.1.5-1.el9_2.3RHSA-2023:5313
open-vm-tools-desktopRocky
Fixed in:0:10.3.0-2.el7_7.3RHSA-2024:5315
Fixed in:0:11.0.5-3.el7_9.7RHSA-2023:5217
Fixed in:0:12.1.5-2.el8_8.3RHSA-2023:5312
Fixed in:0:11.3.5-1.el8_6.4RHSA-2023:5220
Fixed in:0:11.2.0-2.el8_4.3RHSA-2023:5216
Fixed in:0:11.0.0-4.el8_2.3RHSA-2023:5210
Fixed in:0:10.3.10-3.el8_1.4RHSA-2023:5213
Fixed in:0:11.3.5-1.el9_0.4RHSA-2023:5218
open-vm-tools-desktopRed Hat / RHEL
Fixed in:0:10.3.0-2.el7_7.3RHSA-2024:5315

This Red Hat / RHEL release reached end-of-life on 2024-06-30. Extended security maintenance is available until 2029-05-31.

Fixed in:0:11.0.5-3.el7_9.7RHSA-2023:5217

This Red Hat / RHEL release reached end-of-life on 2024-06-30. Extended security maintenance is available until 2029-05-31.

Fixed in:0:11.3.5-1.el8_6.4RHSA-2023:5220
Fixed in:0:12.1.5-2.el8_8.3RHSA-2023:5312
Fixed in:0:11.2.0-2.el8_4.3RHSA-2023:5216
Fixed in:0:11.0.0-4.el8_2.3RHSA-2023:5210
Fixed in:0:10.3.10-3.el8_1.4RHSA-2023:5213
Fixed in:0:11.3.5-1.el9_0.4RHSA-2023:5218
open-vm-tools-desktop-debuginfoRed Hat / RHEL
Fixed in:0:10.3.10-3.el8_1.4RHSA-2023:5213
Fixed in:0:11.2.0-2.el8_4.3RHSA-2023:5216
Fixed in:0:11.3.5-1.el8_6.4RHSA-2023:5220
Fixed in:0:11.0.0-4.el8_2.3RHSA-2023:5210
Fixed in:0:12.1.5-2.el8_8.3RHSA-2023:5312
Fixed in:0:11.3.5-1.el9_0.4RHSA-2023:5218
Fixed in:0:11.3.5-1.el9_0.4RHSA-2023:5218
Fixed in:0:12.1.5-1.el9_2.3RHSA-2023:5313
open-vm-tools-desktop-debuginfoRocky
Fixed in:0:10.3.10-3.el8_1.4RHSA-2023:5213
Fixed in:0:11.3.5-1.el8_6.4RHSA-2023:5220
Fixed in:0:12.1.5-2.el8_8.3RHSA-2023:5312
Fixed in:0:11.0.0-4.el8_2.3RHSA-2023:5210
Fixed in:0:11.2.0-2.el8_4.3RHSA-2023:5216
Fixed in:0:11.3.5-1.el9_0.4RHSA-2023:5218
Fixed in:0:12.1.5-1.el9_2.3RHSA-2023:5313
Fixed in:0:12.1.5-1.el9_2.3RHSA-2023:5313
open-vm-tools-develRocky
Fixed in:0:10.3.0-2.el7_7.3RHSA-2024:5315
Fixed in:0:11.0.5-3.el7_9.7RHSA-2023:5217
open-vm-tools-develRed Hat / RHEL
Fixed in:0:11.0.5-3.el7_9.7RHSA-2023:5217

This Red Hat / RHEL release reached end-of-life on 2024-06-30. Extended security maintenance is available until 2029-05-31.

Fixed in:0:10.3.0-2.el7_7.3RHSA-2024:5315

This Red Hat / RHEL release reached end-of-life on 2024-06-30. Extended security maintenance is available until 2029-05-31.

open-vm-tools-salt-minionRocky
Fixed in:0:12.1.5-2.el8_8.3RHSA-2023:5312
Fixed in:0:12.1.5-1.el9_2.3RHSA-2023:5313
open-vm-tools-salt-minionRed Hat / RHEL
Fixed in:0:12.1.5-2.el8_8.3RHSA-2023:5312
Fixed in:0:12.1.5-1.el9_2.3RHSA-2023:5313
open-vm-tools-sdmpRocky
Fixed in:0:12.1.5-2.el8_8.3RHSA-2023:5312
Fixed in:0:11.3.5-1.el8_6.4RHSA-2023:5220
Fixed in:0:11.2.0-2.el8_4.3RHSA-2023:5216
Fixed in:0:11.3.5-1.el9_0.4RHSA-2023:5218
Fixed in:0:12.1.5-1.el9_2.3RHSA-2023:5313
open-vm-tools-sdmpRed Hat / RHEL
Fixed in:0:12.1.5-2.el8_8.3RHSA-2023:5312
Fixed in:0:11.3.5-1.el8_6.4RHSA-2023:5220
Fixed in:0:11.2.0-2.el8_4.3RHSA-2023:5216
Fixed in:0:11.3.5-1.el9_0.4RHSA-2023:5218
Fixed in:0:12.1.5-1.el9_2.3RHSA-2023:5313
open-vm-tools-sdmp-debuginfoRed Hat / RHEL
Fixed in:0:11.3.5-1.el8_6.4RHSA-2023:5220
Fixed in:0:12.1.5-2.el8_8.3RHSA-2023:5312
Fixed in:0:11.2.0-2.el8_4.3RHSA-2023:5216
Fixed in:0:11.3.5-1.el9_0.4RHSA-2023:5218
Fixed in:0:11.3.5-1.el9_0.4RHSA-2023:5218
Fixed in:0:12.1.5-1.el9_2.3RHSA-2023:5313
Fixed in:0:12.1.5-1.el9_2.3RHSA-2023:5313
open-vm-tools-sdmp-debuginfoRocky
Fixed in:0:11.3.5-1.el8_6.4RHSA-2023:5220
Fixed in:0:11.2.0-2.el8_4.3RHSA-2023:5216
Fixed in:0:12.1.5-2.el8_8.3RHSA-2023:5312
Fixed in:0:11.3.5-1.el9_0.4RHSA-2023:5218
Fixed in:0:11.3.5-1.el9_0.4RHSA-2023:5218
Fixed in:0:12.1.5-1.el9_2.3RHSA-2023:5313
Fixed in:0:12.1.5-1.el9_2.3RHSA-2023:5313

This vulnerability affects an unusually large number of packages. The highest-confidence fixes are shown above; the full list is longer. Check the referenced advisories for complete coverage.

TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorAdjacent
Attack ComplexityHigh
Privileges RequiredLow
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Exploit Intelligence

1.26%probability of exploitation in 30 days
68thpercentile

Moderate risk: more likely to be exploited than 68% of all known CVEs.

References

Related Vulnerabilities

Other CWE-294 vulnerabilities, ordered by exploit likelihood. View all

CVESeverityCVSSEPSSExploitedFix
CVE-2023-23397Critical9.897%KEVFix
CVE-2017-3191Critical9.863%--
CVE-2023-49231Critical9.843%--
CVE-2002-0054High7.522%--
CVE-2022-29593Medium5.914%--
CVE-2022-22806Critical9.812%--

Common questions

How do I fix CVE-2023-20900?

Published advisories record a fix for 35 affected products. The "How to fix" section on this page lists the fixed version and source advisory for each one, so apply the entry matching what you actually run.

Is CVE-2023-20900 being actively exploited?

Not that we know of. CVE-2023-20900 is not in the CISA Known Exploited Vulnerabilities catalog. Its EPSS score of 1.3% is the estimated probability that it will be exploited in the next 30 days. That is higher than 68% of all scored CVEs.

How severe is CVE-2023-20900?

CVE-2023-20900 has a CVSS v3 base score of 7.1, rated high. CVSS rates the technical impact if the vulnerability is exploited, not how likely that is, so weigh it alongside the exploit-prediction score when you decide what to patch first.

What does CVE-2023-20900 affect?

Published advisories record a fix for open-vm-tools (Amazon), open-vm-tools-debuginfo (Amazon), open-vm-tools-debugsource (Amazon), open-vm-tools-desktop (Amazon), and 31 more. Only products with a sourced advisory are listed, so treat this as what we can cite rather than a complete inventory.

Embed a live status badge for CVE-2023-20900
CVE-2023-20900 severity badge

Markdown

[![CVE-2023-20900](https://tridentstack.com/cve/badge/CVE-2023-20900.svg)](https://tridentstack.com/cve/CVE-2023-20900)

HTML

<a href="https://tridentstack.com/cve/CVE-2023-20900"><img src="https://tridentstack.com/cve/badge/CVE-2023-20900.svg" alt="CVE-2023-20900"></a>

Check your Linux endpoints for this class of vulnerability

TridentStack Control continuously scans Linux endpoints for known vulnerabilities and deploys the fixes from the same console. 200 endpoints free forever, no credit card.

Patch your fleet freeStart freeThis CVE lookup is free and always will be.

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-06-17.