CVE-2023-20867 is an authentication-bypass vulnerability in VMware Tools affecting host-to-guest Guest Operations. A fully compromised ESXi host can cause VMware Tools to fail to authenticate host-originated operations directed at a guest virtual machine. This enables an attacker who already controls the hypervisor to interact with guest systems and execute commands without the authentication normally required for those operations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability (unspecified in the content) affecting VMware Tools that is listed as exploited by the threat actor UNC3886/Volt Typhoon.
A VMware ESXi vulnerability referenced as a zero-day used by UNC3886 in targeted intrusions.
An authentication bypass flaw used to execute commands inside guest virtual machines without required authentication in VMware environments.
A vulnerability in VMware Tools leveraged post-compromise to enable direct interaction with guest VMs (via PowerCLI), supporting lateral movement and credential access from VM memory snapshots.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.