A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2023-34059

CVE-2023-34059: VMware Open VM Tools Privilege Escalation

CVE-2023-34059 is a privilege escalation flaw in VMware Open VM Tools allowing non-root users to hijack file descriptors and simulate user inputs. This article covers technical details, affected versions, and remediation.

Updated: May 15, 2026

CVE-2023-34059 Overview

CVE-2023-34059 is a file descriptor hijack vulnerability in the vmware-user-suid-wrapper component of open-vm-tools. A local attacker with non-root privileges on a Linux guest virtual machine can hijack the /dev/uinput file descriptor opened by the SUID wrapper. Once hijacked, the attacker can inject synthetic keyboard and pointer events into the desktop session, effectively simulating user input. The flaw is classified under [CWE-404] (Improper Resource Shutdown or Release) and affects open-vm-tools packaged across major Linux distributions, including Debian 10, 11, and 12.

Critical Impact

Local low-privileged attackers on affected Linux guests can simulate user input via /dev/uinput, enabling keystroke and pointer injection that can drive privileged GUI actions and lead to host-level compromise of the guest session.

Affected Products

  • VMware open-vm-tools (versions prior to the VMSA-2023-0024 fix)
  • Debian GNU/Linux 10, 11, and 12 (open-vm-tools package)
  • Fedora open-vm-tools packages (multiple releases)

Discovery Timeline

  • 2023-10-27 - CVE-2023-34059 published to NVD and disclosed via the Openwall OSS Security mailing list
  • 2023-10-27 - VMware publishes VMSA-2023-0024
  • 2023-11-26 - Follow-up Openwall OSS Security announcement issued
  • 2023-11 - Debian releases DSA-5543 and Debian LTS advisory
  • 2025-03-06 - Last updated in NVD database

Technical Details for CVE-2023-34059

Vulnerability Analysis

The vmware-user-suid-wrapper binary is installed setuid-root to enable specific privileged operations required by the open-vm-tools user agent. One such operation is opening /dev/uinput, the Linux user-space input device that allows a process to inject synthetic input events into the kernel input subsystem. The SUID wrapper opens this device with elevated privileges, then passes the file descriptor to the non-privileged vmtoolsd user process.

The vulnerability stems from improper handling of this file descriptor across the privilege boundary. A local attacker can manipulate the wrapper's execution environment so that the descriptor is inherited or accessible to an attacker-controlled process instead of the intended consumer. Once the attacker holds a writable handle to /dev/uinput, they can craft input_event structures to deliver arbitrary keystrokes and mouse events to the active session.

Root Cause

The root cause is an improper resource lifecycle defect [CWE-404] in the SUID wrapper. The wrapper acquires a privileged file descriptor to /dev/uinput but fails to ensure the descriptor is transferred or scoped exclusively to the legitimate target process. Race conditions or process manipulation by a co-resident local user allow the descriptor to be hijacked before the intended handoff completes.

Attack Vector

Exploitation requires local access with low privileges on a Linux guest running a vulnerable open-vm-tools. The attacker races or interposes against vmware-user-suid-wrapper to capture the inherited /dev/uinput descriptor. With that descriptor, they can write structured input events to the kernel, simulating keystrokes that target any application currently focused in the desktop session. This can drive privileged GUI prompts, unlock screens, or launch commands in a higher-privileged user's terminal.

No public proof-of-concept exploit code is currently listed for this CVE. Refer to the VMware advisory VMSA-2023-0024 and the Openwall disclosure thread for technical specifics.

Detection Methods for CVE-2023-34059

Indicators of Compromise

  • Unexpected processes holding open file descriptors to /dev/uinput that are not vmtoolsd or known input daemons.
  • Unexplained keystroke or pointer activity in guest GUI sessions when no user is present.
  • Non-root processes inheriting descriptors originally opened by vmware-user-suid-wrapper.

Detection Strategies

  • Audit running open-vm-tools package versions across Linux guests and flag any below the fixed releases shipped in VMSA-2023-0024 and DSA-5543.
  • Use lsof /dev/uinput and fuser /dev/uinput to enumerate processes with the input device open, alerting on unexpected UIDs or binary paths.
  • Enable Linux auditd rules to record execve of vmware-user-suid-wrapper and open syscalls against /dev/uinput, correlating parent-child process relationships.

Monitoring Recommendations

  • Forward auditd, journald, and EDR telemetry from Linux guests to a centralized data lake for cross-host correlation.
  • Alert on local privilege escalation indicators such as non-interactive processes invoking SUID binaries followed by GUI input events.
  • Track package inventory drift on virtualized Linux fleets to confirm patch deployment status of open-vm-tools.

How to Mitigate CVE-2023-34059

Immediate Actions Required

  • Patch open-vm-tools on all affected Linux guests using the fixed packages from VMware, Debian, and Fedora.
  • Restrict local interactive and shell access on multi-user Linux guests to trusted accounts only.
  • Audit installations to confirm the vmware-user-suid-wrapper binary belongs to a patched package version.

Patch Information

VMware released fixed versions of open-vm-tools documented in VMSA-2023-0024. Debian published fixes in DSA-5543 and the corresponding Debian LTS advisory. Fedora distributed updated builds through the Fedora package-announce list. Apply the vendor-supplied package for your distribution and restart vmtoolsd or reboot the guest to ensure the new binary is loaded.

Workarounds

  • Remove the setuid bit from vmware-user-suid-wrapper if the input-injection features are not required, accepting the loss of related guest functionality.
  • Restrict access to /dev/uinput through udev rules or kernel module controls so that only trusted services can open it.
  • Limit shell access on affected guests to reduce the local attack surface until patches are deployed.
bash
# Configuration example: verify patched package and restrict /dev/uinput
# Debian/Ubuntu
sudo apt update && sudo apt install --only-upgrade open-vm-tools
dpkg -l open-vm-tools

# Fedora
sudo dnf upgrade open-vm-tools
rpm -q open-vm-tools

# Inspect SUID wrapper and active openers of /dev/uinput
ls -l /usr/bin/vmware-user-suid-wrapper
sudo lsof /dev/uinput

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypePrivilege Escalation

  • Vendor/TechVmware

  • SeverityHIGH

  • CVSS Score7.0

  • EPSS Probability0.08%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Impact Assessment
  • ConfidentialityHigh
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • NVD-CWE-noinfo

  • CWE-404
  • Technical References
  • Openwall OSS Security Update

  • Openwall OSS Security Announcement

  • Openwall OSS Security Update

  • Debian LTS Security Announcement

  • Fedora Package Update Notification

  • Fedora Package Update Notification

  • Fedora Package Update Notification

  • Debian Security Advisory DSA-5543

  • VMware Security Advisory VMSA-2023-0024

  • Openwall OSS Security Update
  • Vendor Resources
  • Openwall OSS Security Update
  • Related CVEs
  • CVE-2025-62624: VMware ESXi Privilege Escalation Flaw

  • CVE-2025-62623: VMware ESXi Privilege Escalation Flaw

  • CVE-2026-22716: VMware Workstation Privilege Escalation

  • CVE-2026-22715: VMware Workstation Privilege Escalation
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English