cbcvebase.
CVE-2023-20892
published 2023-06-22

CVE-2023-20892: The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious…

PriorityP258critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.85%
76.7th percentile
The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts vCenter Server.

Affected

7 ranges
VendorProductVersion rangeFixed in
vmwarevcenter_server< 7.07.0
vmwarevcenter_server
vmwarevcenter_server
vmwarevmware_cloud_foundation>= 4.x < 7.0 U3m, 8.0 U1b7.0 U3m, 8.0 U1b
vmwarevmware_cloud_foundation>= 5.x < 7.0 U3m, 8.0 U1b7.0 U3m, 8.0 U1b
vmwarevmware_vcenter_server>= 7.0 < 7.0 u3m7.0 u3m
vmwarevmware_vcenter_server>= 8.0 < 8.0 U1b8.0 U1b

Detection & IOCsextracted from sources · hover to see the quote

  • Target attack surface is vCenter Server's DCERPC protocol implementation — monitor for anomalous or malformed DCERPC traffic directed at vCenter Server network endpoints
  • Vulnerability class is heap overflow via uninitialized memory in DCERPC — look for unexpected process crashes, memory corruption signals, or anomalous child process spawning from vCenter Server DCERPC service components
  • Affected products include VMware vCenter Server and VMware Cloud Foundation — ensure detection coverage spans both platforms when hunting for exploitation attempts
  • ·CVE-2023-20892 is one of five related memory corruption CVEs addressed together in VMSA-2023-0014; detections should account for the full CVE cluster to avoid gaps
  • ·Exploitation requires only network access to vCenter Server — no authentication is mentioned, meaning the attack surface is broad and perimeter-level controls (firewall rules restricting DCERPC/RPC ports to vCenter) are a critical compensating control
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.