⚠ Actively exploited
Added to CISA KEV on 2024-01-22. Federal agencies required to patch by 2024-02-12. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..

CVE-2023-34048

CWE-787Out-of-bounds Write10 documents8 sources
Severity
9.8CRITICAL
EPSS
93.2%
top 0.20%
CISA KEV
KEV
Added 2024-01-22
Due 2024-02-12
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedOct 25
KEV addedJan 22
KEV dueFeb 12
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

🔴Vulnerability Details

3
CVEList
VMware vCenter Server Out-of-Bounds Write Vulnerability2023-10-25
GHSA
GHSA-87j2-5g9j-7jmv: vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol2023-10-25
VulnCheck
VMware vCenter Server Out-of-Bounds Write Vulnerability2023

💥Exploits & PoCs

1
Nuclei
VMware vCenter Server - Out-of-Bounds Write

📋Vendor Advisories

2
CISA
VMware vCenter Server Out-of-Bounds Write Vulnerability2024-01-22
VMware
VMware vCenter Server updates address out-of-bounds write and information disclosure vulnerabilities (CVE-2023-34048, CVE-2023-34056)2023-10-25

🕵️Threat Intelligence

3
Bleepingcomputer
Chinese hackers exploit VMware bug as zero-day for two years2024-01-19
Bleepingcomputer
VMware confirms critical vCenter flaw now exploited in attacks2024-01-19
Bleepingcomputer
VMware fixes critical code execution flaw in vCenter Server2023-10-25