CVEFinder.io

CVE-2023-20900

⚠️ high
🔍 Scan for this CVE
Summary

A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .

CVSS Score
7.1
High
EPSS Score
0.8
Exploit Probability
Published Date
2023-08-31
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 53.4% of all 322,139 vulnerabilities in our database.

#150,107
Above average severity
Severity Percentile
Last Modified 2024-11-21
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE IDs (Weakness Types)

📦 Affected Products 10

🔗 References 9

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-31431 ⚠️ high 7.8 2.6 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-pla... 2026-04-22
CVE-2026-35093 ⚠️ high 8.8 0.0 A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or ... 2026-04-01
CVE-2026-35094 ℹ️ low 3.3 0.0 A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can expl... 2026-04-01
CVE-2026-4775 ⚠️ high 7.8 0.0 A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the ... 2026-03-24
CVE-2026-1940 🔶 medium 5.1 0.0 An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added... 2026-03-23
CVE-2025-63261 ⚠️ high 7.8 0.1 AWStats 8.0 is vulnerable to Command Injection via the open function 2026-03-20
These CVEs affect the same products