cbcvebase.
CVE-2023-20894
published 2023-06-22

CVE-2023-20894: The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to…

PriorityP271critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
33.95%
98.2th percentile
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.

Affected

7 ranges
VendorProductVersion rangeFixed in
vmwarevcenter_server< 7.07.0
vmwarevcenter_server
vmwarevcenter_server
vmwarevmware_cloud_foundation>= 4.x < 7.0 U3m, 8.0 U1b7.0 U3m, 8.0 U1b
vmwarevmware_cloud_foundation>= 5.x < 7.0 U3m, 8.0 U1b7.0 U3m, 8.0 U1b
vmwarevmware_vcenter_server>= 7.0 < 7.0 u3m7.0 u3m
vmwarevmware_vcenter_server>= 8.0 < 8.0 U1b8.0 U1b

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for specially crafted DCERPC protocol packets sent to vCenter Server over the network, which may indicate exploitation attempts targeting the out-of-bounds write vulnerability
  • Focus detection on DCERPC protocol traffic directed at vCenter Server endpoints; anomalous or malformed DCERPC packets should be flagged for investigation
  • ·This vulnerability affects VMware vCenter Server and VMware Cloud Foundation; ensure patching scope covers both products as addressed in VMSA-2023-0014
  • ·CVE-2023-20894 is one of five related memory corruption CVEs (CVE-2023-20892 through CVE-2023-20896) addressed together; detection and patching should account for all five
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.