CVE-2023-20864
published 2023-04-20CVE-2023-20864: VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for…
PriorityP183critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
70.42%
99.3th percentile
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | aria_operations_for_logs | >= 8.10.2 < 8.12.0 | 8.12.0 |
| vmware | cloud_foundation | 4.0 – 4.5 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Traffic on ports 9543 may be TLS-encrypted; SSL/TLS inspection is required before applying byte-level detection signatures for this vulnerability. ↗
- →The Nuclei PoC template uses a DNS-based OAST callback (interactsh) to confirm exploitation; network-level detection of outbound DNS queries from VMware Aria Operations for Logs hosts following inbound POST requests to /api/v2/internal/cluster/applyMembership may indicate successful exploitation. ↗
- →The Nuclei PoC template checks for the string '"errorMessage":"Internal error' in the HTTP response body as a secondary confirmation of a vulnerable target. ↗
- ·CVE-2023-20864 only affects VMware Aria Operations for Logs version 8.10.2; other versions are not vulnerable to this specific deserialization flaw (though they may be vulnerable to CVE-2023-20865). ↗
- ·The expected Class Name embedded in the serialized object for each API endpoint may change in future versions of the software, requiring detection signature updates. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8xj6-cxx5-jf7j: VMware Aria Operations for Logs contains a deserialization vulnerability
ghsa_unreviewed·2023-04-20
CVE-2023-20864 [CRITICAL] CWE-502 GHSA-8xj6-cxx5-jf7j: VMware Aria Operations for Logs contains a deserialization vulnerability
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
VMware
VMware Aria Operations for Logs (Operations for Logs) update addresses multiple vulnerabilities. (CVE-2023-20864, CVE-2023-20865)
vendor_vmware·2023-04-20·CVSS 9.8
CVE-2023-20864 [CRITICAL] VMware Aria Operations for Logs (Operations for Logs) update addresses multiple vulnerabilities. (CVE-2023-20864, CVE-2023-20865)
VMSA-2023-0007: VMware Aria Operations for Logs (Operations for Logs) update addresses multiple vulnerabilities. (CVE-2023-20864, CVE-2023-20865)
VMware Aria Operations for Logs contains a deserialization vulnerability. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVEs: CVE-2023-20864, CVE-2023-20865
Affected products: VMware Aria, VMware Cloud Foundation
No detection rules found.
Nuclei
VMware Aria Operations for Logs - Unauthenticated Remote Code Execution
nuclei·CVSS 9.8
CVE-2023-20864 [CRITICAL] VMware Aria Operations for Logs - Unauthenticated Remote Code Execution
VMware Aria Operations for Logs - Unauthenticated Remote Code Execution
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
Template:
id: CVE-2023-20864
info:
name: VMware Aria Operations for Logs - Unauthenticated Remote Code Execution
author: rootxharsh,iamnoooob,pdresearch
severity: critical
description: |
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the
Checkpoint
3rd July – Threat Intelligence Report
blogs_checkpoint·2023-07-03
CVE-2020-12641 3rd July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 3rd July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 3rd July, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
The LockBit ransomware group has recently claimed responsibility for hacking the Taiwan Semiconductor Manufacturing Company (TSMC), the largest contract chip manufacturer globally, serving tech giants such as Apple and Qualcomm. TSMC denied it was breached by Lockbit, but confirmed that the group has breached one of the company’s I
Trendmicro
Remote Code Execution in VMware Aria Operations for Logs
blogs_trendmicro·2023-06-29·CVSS 9.8
CVE-2023-20864 [CRITICAL] Remote Code Execution in VMware Aria Operations for Logs
# CVE-2023-20864: Remote Code Execution in VMware Aria Operations for Logs
Discover remote code execution in VMware Aria operations for logs.
By: Trend Micro Research
2023/06/29
Read time: ( words)
Save to Folio
In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Jonathan Lein and Dusan Stevanovic of the Trend Micro Research Team detail a recently patched remote code execution vulnerability in VMware Aria Operations for Logs (formerly vRealize). This bug was originally submitted to the ZDI program by an anonymous researcher. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of root. Similar bugs ar
Trendmicro
Remote Code Execution in VMware Aria Operations for Logs
blogs_trendmicro·2023-06-29·CVSS 9.8
CVE-2023-20864 [CRITICAL] Remote Code Execution in VMware Aria Operations for Logs
## CVE-2023-20864: Remote Code Execution in VMware Aria Operations for Logs
Discover remote code execution in VMware Aria operations for logs.
By: Trend Micro Research Jun 29, 2023 Read time: ( words)
Save to Folio
In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Jonathan Lein and Dusan Stevanovic of the Trend Micro Research Team detail a recently patched remote code execution vulnerability in VMware Aria Operations for Logs (formerly vRealize). This bug was originally submitted to the ZDI program by an anonymous researcher. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of root. Similar bugs
Trendmicro
Remote Code Execution in VMware Aria Operations for Logs
blogs_trendmicro·2023-06-29·CVSS 9.8
CVE-2023-20864 [CRITICAL] Remote Code Execution in VMware Aria Operations for Logs
## CVE-2023-20864: Remote Code Execution in VMware Aria Operations for Logs
Discover remote code execution in VMware Aria operations for logs.
By: Trend Micro Research 2023/06/29 Read time: ( words)
Save to Folio
In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Jonathan Lein and Dusan Stevanovic of the Trend Micro Research Team detail a recently patched remote code execution vulnerability in VMware Aria Operations for Logs (formerly vRealize). This bug was originally submitted to the ZDI program by an anonymous researcher. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of root. Similar bugs ar
Tenable
CVE-2023-20864: VMware Aria Operations for Logs Deserialization Vulnerability
blogs_tenable·2023-04-21·CVSS 9.8
[CRITICAL] CVE-2023-20864: VMware Aria Operations for Logs Deserialization Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Greynoiseio
GreyNoise Round-Up: Product Updates
blogs_greynoiseio
GreyNoise Round-Up: Product Updates
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2023-04-20
Published