CVE-2023-20892
published 2023-06-22CVE-2023-20892: The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious…
PriorityP258critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.85%
76.7th percentile
The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts vCenter Server.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | < 7.0 | 7.0 |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vmware_cloud_foundation | >= 4.x < 7.0 U3m, 8.0 U1b | 7.0 U3m, 8.0 U1b |
| vmware | vmware_cloud_foundation | >= 5.x < 7.0 U3m, 8.0 U1b | 7.0 U3m, 8.0 U1b |
| vmware | vmware_vcenter_server | >= 7.0 < 7.0 u3m | 7.0 u3m |
| vmware | vmware_vcenter_server | >= 8.0 < 8.0 U1b | 8.0 U1b |
Detection & IOCsextracted from sources · hover to see the quote
- →Target attack surface is vCenter Server's DCERPC protocol implementation — monitor for anomalous or malformed DCERPC traffic directed at vCenter Server network endpoints ↗
- →Vulnerability class is heap overflow via uninitialized memory in DCERPC — look for unexpected process crashes, memory corruption signals, or anomalous child process spawning from vCenter Server DCERPC service components ↗
- →Affected products include VMware vCenter Server and VMware Cloud Foundation — ensure detection coverage spans both platforms when hunting for exploitation attempts ↗
- ·CVE-2023-20892 is one of five related memory corruption CVEs addressed together in VMSA-2023-0014; detections should account for the full CVE cluster to avoid gaps ↗
- ·Exploitation requires only network access to vCenter Server — no authentication is mentioned, meaning the attack surface is broad and perimeter-level controls (firewall rules restricting DCERPC/RPC ports to vCenter) are a critical compensating control ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vmcx-3r5m-96cr: The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol
ghsa_unreviewed·2023-06-22
CVE-2023-20892 [CRITICAL] CWE-787 GHSA-vmcx-3r5m-96cr: The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol
The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts vCenter Server.
VMware
VMware vCenter Server updates address multiple memory corruption vulnerabilities (CVE-2023-20892, CVE-2023-20893, CVE-2023-20894, CVE-2023-20895, CVE-2023-20896)
vendor_vmware·2023-06-22·CVSS 8.1
CVE-2023-20892 [HIGH] VMware vCenter Server updates address multiple memory corruption vulnerabilities (CVE-2023-20892, CVE-2023-20893, CVE-2023-20894, CVE-2023-20895, CVE-2023-20896)
VMSA-2023-0014: VMware vCenter Server updates address multiple memory corruption vulnerabilities (CVE-2023-20892, CVE-2023-20893, CVE-2023-20894, CVE-2023-20895, CVE-2023-20896)
VMware Cloud Foundation VMware Cloud Foundation VMware vCenter Server
CVEs: CVE-2023-20892, CVE-2023-20893, CVE-2023-20894, CVE-2023-20895, CVE-2023-20896
Affected products: VMware Cloud Foundation, VMware vCenter Server, vSphere
No detection rules found.
No public exploits indexed.
Talos
Uncovering weaknesses in Apple macOS and VMWare vCenter: 12 vulnerabilities in RPC implementation
blogs_talos·2023-07-13
Uncovering weaknesses in Apple macOS and VMWare vCenter: 12 vulnerabilities in RPC implementation
- Cisco Talos discovered 12 memory corruption vulnerabilities in MSRPC implementations on Apple macOS and VMWare vCenter.
- Seven vulnerabilities affect Apple macOS only.
- Two vulnerabilities affect VMWare vCenter.
- Three vulnerabilities affect both.
- For more on these individual vulnerabilities, read Talos’ advisories on the issues here.
- MSRPC implementations on macOS and vCenter are based on the same DCERPC codebase, forked at different times and modified to suit different use cases
- Uncovered issues fall into use-after-free, buffer-overflow, information leak and denial-of-service vulnerability classes. Some of these could be combined to achieve remote code execution or privilege escalation.
- Apple has addressed all of the vulnerabilities on three separate occasions in their sched
Talos
Uncovering weaknesses in Apple macOS and VMWare vCenter: 12 vulnerabilities in RPC implementation
blogs_talos·2023-07-13
Uncovering weaknesses in Apple macOS and VMWare vCenter: 12 vulnerabilities in RPC implementation
## Uncovering weaknesses in Apple macOS and VMWare vCenter: 12 vulnerabilities in RPC implementation
Cisco Talos discovered 12 memory corruption vulnerabilities in MSRPC implementations on Apple macOS and VMWare vCenter. - Seven vulnerabilities affect Apple macOS only. - Two vulnerabilities affect VMWare vCenter. - Three vulnerabilities affect both.
For more on these individual vulnerabilities, read Talos’ advisories on the issues here .
MSRPC implementations on macOS and vCenter are based on the same DCERPC codebase, forked at different times and modified to suit different use cases
Uncovered issues fall into use-after-free, buffer-overflow, information leak and denial-of-service vulnerability classes. Some of these could be combined to achieve remote code execution or privilege escal
2023-06-22
Published