cbcvebase.
CVE-2023-20893
published 2023-06-22

CVE-2023-20893: The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to…

PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.25%
66.0th percentile
The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.

Affected

7 ranges
VendorProductVersion rangeFixed in
vmwarevcenter_server< 7.07.0
vmwarevcenter_server
vmwarevcenter_server
vmwarevmware_cloud_foundation>= 4.x < 7.0 U3m, 8.0 U1b7.0 U3m, 8.0 U1b
vmwarevmware_cloud_foundation>= 5.x < 7.0 U3m, 8.0 U1b7.0 U3m, 8.0 U1b
vmwarevmware_vcenter_server>= 7.0 < 7.0 u3m7.0 u3m
vmwarevmware_vcenter_server>= 8.0 < 8.0 U1b8.0 U1b

Detection & IOCsextracted from sources · hover to see the quote

  • Target service is vCenter Server's DCERPC protocol implementation — monitor for anomalous or malformed DCERPC traffic directed at vCenter Server network endpoints
  • Vulnerability class is use-after-free in the DCERPC protocol handler — look for unexpected process crashes, memory corruption signals, or anomalous child process spawning from vCenter Server DCERPC service components
  • Affected products include VMware vCenter Server and VMware Cloud Foundation — prioritize patching and network-level monitoring on these platforms for exploitation attempts
  • ·Exploitation requires only network access to vCenter Server — no authentication is mentioned as a prerequisite, meaning the attack surface is any host with network reachability to vCenter
  • ·This CVE is part of a cluster of five memory corruption vulnerabilities (CVE-2023-20892 through CVE-2023-20896) addressed in the same advisory — detections and patches should account for all five
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.