κατασκευή ιστοσελίδων ρόδος

TECH - WEB DEVELOPMENT NEWS

Get the latest tech - web development news and analysis on industry around the world.

  • HOME
You are here: Home / INDUSTRY NEWS / PoC exploit Released for VMware Workstation guest-to-host escape Vulnerability
άμυνα
.

PoC exploit Released for VMware Workstation guest-to-host escape Vulnerability

02/10/2025

A proof-of-concept (PoC) exploit has been released for a critical vulnerability chain in VMware Workstation that allows an attacker to escape from a guest virtual machine and execute arbitrary code on the host operating system.

The exploit successfully chains together an information leak and a stack-based buffer overflow vulnerability to achieve a full guest-to-host escape, one of the most severe types of security flaws in virtualization software.

The exploit targets vulnerabilities that were first demonstrated at the Pwn2Own Vancouver event in 2023. Security researcher Alexander Zaviyalov of NCC Group recently published a detailed technical analysis and a functional PoC, demonstrating the practical risk posed by these flaws.

The Two-Stage Attack

The guest-to-host escape is accomplished by chaining two distinct vulnerabilities found in the virtual Bluetooth device functionality of VMware Workstation. This feature, which is enabled by default, allows a guest VM to use the host’s Bluetooth adapter.

Information Leak (CVE-2023-20870, CVE-2023-34044): The first stage of the attack leverages a Use-After-Free (UAF) memory leak. By sending specifically crafted USB Request Block (URB) control transfers to the virtual mouse and Bluetooth devices, an attacker can leak memory pointers from the vmware-vmx.exe process on the host.

This information leak is crucial for bypassing Address Space Layout Randomization (ASLR), a standard security feature that randomizes memory locations to make exploitation more difficult.

    Exploit

    Buffer Overflow (CVE-2023-20869): With ASLR bypassed, the attacker proceeds to the second stage. This involves triggering a stack-based buffer overflow by sending a malicious Service Discovery Protocol (SDP) packet from the guest VM to another Bluetooth device discoverable by the host.

    The overflow allows the attacker to hijack the program’s execution flow, and with the previously leaked memory addresses, they can execute a custom payload on the host system.

      The combination of these vulnerabilities allows an attacker with control over a guest VM to gain full control of the host machine. In the demonstration, the exploit successfully launched a reverse shell from a Linux guest to a fully patched Windows 11 host, effectively compromising the underlying system, Alexander Zaviyalov said.

      The full exploit chain primarily affects VMware Workstation 17.0.1 and earlier versions. The specific vulnerabilities have different patch timelines:

      • The stack-based buffer overflow (CVE-2023-20869) was addressed in version 17.0.2.vmware-workstation-guest-to-host-escape.pdf
      • The memory leak vulnerabilities (CVE-2023-20870 and CVE-2023-34044) were patched across versions 17.0.2 and 17.5.0, respectively.vmware-workstation-guest-to-host-escape.pdf

      Because the complete exploit requires both the buffer overflow and the memory leak, users running version 17.0.1 or older are at the highest risk.

      Mitigations

      The primary recommendation for all users is to update their VMware Workstation software to the latest available version (17.5.0 or newer), which contains patches for all the discussed vulnerabilities.

      For users who cannot immediately update, a potential workaround is to disable the virtual Bluetooth device. This can be done by unchecking the “Share Bluetooth devices with the virtual machine” option in the virtual machine’s USB Controller settings.

      Disabling this feature removes the attack surface exploited by this specific PoC. The detailed research highlights the complexity of modern exploits and underscores the importance of timely patching for virtualization platforms.

      Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

      Source: cybersecuritynews.com

      Filed Under: INDUSTRY NEWS Tagged With: Source-10

      Your RAM has more than one XMP profile, and here's when to use the others

      Enabling XMP or EXPO in the motherboard's BIOS is one of the first things all enthusiasts do after building a new PC. It's an easy way to ensure that you're getting the RAM speed you paid for, and often times doesn't compromise stability. They stand for eXtreme Memory Profile and Extended Profiles for Overclocking, and are different flavors of RAM overclocking validation for Intel and AMD, … [Read More...]

      Ditching smart home subscriptions for open-source Home Assistant

      I quickly grew tired of having countless smart home subscriptions to create the ultimate tech-laden household. And it's not just the usual suspects, like an alarm system, network switches, or some bulbs requiring cloud support plans. Almost everything you can purchase for the "smart home" can come packing some advanced features that require some sort of recurring fee. Like media subscriptions such … [Read More...]

      I migrated my cloud photos to my self-hosted Immich, here's how

      Like most people, I've been on the Google Photos bandwagon for years now. Photos of trips, birthdays, receipts, and random food snaps have all been backed up to Google Photos. Initially, it was free and convenient as an add-on perk with my Pixel phone. Over time, I ran into the same problems as everyone else. While the perk disappeared, I was locked in, and my growing library pushed me towards … [Read More...]

      I replaced Adobe Premiere with DaVinci Resolve, and I'm not missing out on anything

      Leaving my Adobe subscriptions behind felt like a gamble at first. Some tools were easy to replace, especially since there are so many great open-source graphics apps out there. But some were harder to replace – finding a decent alternative for After Effects felt like it took forever. And then there was also Premiere Pro. Source: xda-developers.com … [Read More...]

      You have to play these Mario games before the Super Mario Galaxy Movie comes out in 2026

      Nintendo announced the sequel to The Super Mario Bros. Movie will be hitting theaters on April 3, 2026. The follow-up is titled The Super Mario Galaxy Movie, and was revealed during the Sepember 2025 Nintendo Direct Presentation as part of the celebration of the 40th anniversary of the Super Mario series. To commemorate the occasion, Nintendo is releasing multiple Mario games for the Nintendo … [Read More...]

      This week’s best deal is a ‘kids’ Kindle Paperwhite that’s better than the adult version

      Our other favorite deals from this week include refurbished Sonos gear and the 8BitDo Ultimate 2 controller.Oct 4, 2025, 5:00 PM UTCSheena Vasani writes about tech news, reviews gadgets, and helps readers save money by highlighting deals and product recommendations for The Verge.Amazon’s Prime Big Deal Days may bring some great Kindle deals, but if you can’t wait, you don’t have to. Right now, the … [Read More...]

      Vicinae is basically Raycast for Linux, and it's (almost) everything I wanted

      Recently, I've written quite a bit about Raycast, and how it's my absolute favorite app on macOS, and now on Windows as well, thanks to the recent beta launch. But outside of macOS, I'm more of a Linux user these days, and I recently expressed my wish that Raycast would come there, too. Source: xda-developers.com … [Read More...]

      Microsoft sneakily drops DLC discounts that come with Xbox Game Pass

      After Microsoft decided to jack up the price of its Xbox Game Pass subscriptions to up to $30 a month, it has another unwelcome surprise for members. In a statement provided to multiple outlets like Insider Gaming, a spokesperson for Microsoft confirmed it has removed the discounts for DLC that come with a Game Pass subscription, replacing them by offering points for its Rewards program.While … [Read More...]

      The best Amazon Prime Day deals under $50: Early sales on tech from Apple, Anker, Ring, JBL, Roku and others

      Prime Day sales are a great opportunity to nab an expensive bit of shiny new tech you’ve been eying — it’s also an excellent time to get a discount on smaller electronics and accessories. For this list, we compared what’s on sale right now with the stuff we recommend in our guides. For less than $50 each, we found deals on some of our favorite tech including batteries, iPhone paraphernalia, mice, … [Read More...]

      4 Linux kernel tweaks I made that actually improved performance

      If you want something that offers stability, flexibility, and performance, you'll want to consider a Linux distribution. A major part of what makes this operating system (OS) such an easy recommendation is the kernel, the core of what makes everything work. The Linux kernel manages everything from scheduling processes to managing memory allocation and device communication. It's so good that you … [Read More...]

      Tags

      Source-1 Source-2 Source-3 Source-4 Source-5 Source-6 Source-7 Source-8 Source-9 Source-10 Source-12 Source-13 Source-15 Source-16

      Tech Web Development News

      This is a PERSONAL and PRIVATE WEBPAGE. Please leave this page. Contact me via email : admin@news-6.com about anything you would like to ask or problem.

      Tech News

      Disclaimer!
      In every post is written below the original source of the post. Copyrights belong on their owners.

      Web Development News

      HOTELS – CRUISES – CARS – TRAVEL

      Recent Posts

      • Your RAM has more than one XMP profile, and here's when to use the others
      • Ditching smart home subscriptions for open-source Home Assistant
      • I migrated my cloud photos to my self-hosted Immich, here's how
      • I replaced Adobe Premiere with DaVinci Resolve, and I'm not missing out on anything
      • You have to play these Mario games before the Super Mario Galaxy Movie comes out in 2026

      Technology - Seo

      Categories

      • INDUSTRY NEWS

      World Industry News

      Privacy & Cookies: This site uses cookies.
      To find out more, as well as how to remove or block these, see here: Our Cookie Policy
      TECH - WEB DEVELOPMENT NEWS @ COPYRIGHTS 2023