Theori published a series of technical disclosures showing how multiple known vulnerabilities could be chained into full-system compromise across enterprise environments. In VMware Workstation, the researchers described CVE-2023-34044, an information leak in the virtual Bluetooth device that exposed uninitialized host memory and could reveal vmware-vmx.exe addresses, and CVE-2023-20869, a stack-based memory corruption flaw in SDP packet handling that enabled guest-to-host code execution through the virtual Bluetooth device. The VMware bugs were presented as parts of a broader escape chain, with related Bluetooth and URB processing details aligning with prior public research from ZDI on VMware Workstation exploitation.
The same research series also examined Windows kernel privilege-escalation bugs in mskssrv.sys, including CVE-2023-29360, which abused MmProbeAndLockPages with KernelMode to gain arbitrary kernel read/write and elevate from medium integrity to SYSTEM, and CVE-2023-36802, a type-confusion flaw that could be turned into a PreviousMode overwrite for SYSTEM-level access. Separately, Theori disclosed four critical flaws in CoSoSys Endpoint Protector—CVE-2024-36072 through CVE-2024-36075—that could be chained from unauthenticated server access to root command execution, plaintext credential theft, and compromise of managed macOS and Windows endpoints; Netwrix, which now owns the product, patched the issues before public disclosure.

Get the actors, campaigns, and ATT&CK mapping behind it.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
6 references tracked. Mallory keeps watching after this page renders.
theori.io
Open sourcetheori.io
Open sourcetheori.io
Open sourcetheori.io
Open sourcetheori.io
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.