CVE-2023-20893
published 2023-06-22CVE-2023-20893: The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to…
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | < 7.0 | 7.0 |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vmware_cloud_foundation | >= 4.x < 7.0 U3m, 8.0 U1b | 7.0 U3m, 8.0 U1b |
| vmware | vmware_cloud_foundation | >= 5.x < 7.0 U3m, 8.0 U1b | 7.0 U3m, 8.0 U1b |
| vmware | vmware_vcenter_server | >= 7.0 < 7.0 u3m | 7.0 u3m |
| vmware | vmware_vcenter_server | >= 8.0 < 8.0 U1b | 8.0 U1b |