CVE-2023-34048
published 2023-10-25CVE-2023-34048: vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter…
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2024-02-12
Exploited in the wild
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | 4.0 – 5.5 | — |
| vmware | vmware_cloud_foundation | — | — |
| vmware | vmware_cloud_foundation | — | — |
| vmware | vmware_vcenter_server | >= 7.0 < 7.0U3o | 7.0U3o |
| vmware | vmware_vcenter_server | >= 8.0 < 8.0U2 | 8.0U2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL