cbcvebase.

Vmware Cloud Foundation vulnerabilities

12 known vulnerabilities affecting vmware/vmware_cloud_foundation.

Total CVEs
12
CISA KEV
3
actively exploited
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL5HIGH5MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2023-34048P1CRITICALCVSS 9.8KEVPoCv5.xv4.x2023-10-25
CVE-2023-34048 [CRITICAL] CWE-787 CVE-2023-34048: vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC pro vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.
nvd
CVE-2025-41244P1HIGHCVSS 7.8KEVPoC≥ 5.x, < 8.18.5≥ 4.x, < 8.18.52025-09-29
CVE-2025-41244 [HIGH] CWE-267 CVE-2025-41244: VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malici VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
nvd
CVE-2025-22224P1HIGHCVSS 8.2KEVRansomwarev5.x, 4.5.x2025-03-04
CVE-2025-22224 [HIGH] CWE-367 CVE-2025-22224: VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads t VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
nvd
CVE-2023-20894P2CRITICALCVSS 9.8≥ 5.x, < 7.0 U3m, 8.0 U1b≥ 4.x, < 7.0 U3m, 8.0 U1b2023-06-22
CVE-2023-20894 [CRITICAL] CWE-787 CVE-2023-20894: The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.
nvd
CVE-2023-20892P2CRITICALCVSS 9.8≥ 5.x, < 7.0 U3m, 8.0 U1b≥ 4.x, < 7.0 U3m, 8.0 U1b2023-06-22
CVE-2023-20892 [CRITICAL] CWE-787 CVE-2023-20892: The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory i The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts vCenter Server.
nvd
CVE-2023-20893P3CRITICALCVSS 9.8≥ 5.x, < 7.0 U3m, 8.0 U1b≥ 4.x, < 7.0 U3m, 8.0 U1b2023-06-22
CVE-2023-20893 [CRITICAL] CWE-416 CVE-2023-20893: The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERP The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.
nvd
CVE-2023-20895P3CRITICALCVSS 9.8≥ 5.x, < 7.0 U3m, 8.0 U1b≥ 4.x, < 7.0 U3m, 8.0 U1b2023-06-22
CVE-2023-20895 [CRITICAL] CWE-787 CVE-2023-20895: The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DC The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.
nvd
CVE-2026-22721P3HIGHCVSS 7.2≥ 4.0, < 5.2.3≥ 9.0, < 9.0.22026-02-25
CVE-2026-22721 [HIGH] CWE-269 CVE-2026-22721: VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privile VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found in VMS
nvd
CVE-2023-20896P3HIGHCVSS 7.5≥ 5.x, < 7.0 U3m, 8.0 U1b≥ 4.x, < 7.0 U3m, 8.0 U1b2023-06-22
CVE-2023-20896 [HIGH] CWE-125 CVE-2023-20896: The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and vmafdd).
nvd
CVE-2025-22249P3HIGHCVSS 8.2≥ 5.x, < 8.18.1 patch 2≥ 4.x, < 8.18.1 patch 22025-05-13
CVE-2025-22249 [HIGH] CWE-79 CVE-2025-22249: VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious ac VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.
nvd
CVE-2025-22215P4MEDIUMCVSS 4.3≥ 5.x, < 8.18.1 patch 1≥ 4.x, < 8.18.1 patch 12025-01-08
CVE-2025-22215 [MEDIUM] CWE-918 CVE-2025-22215: VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious acto VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network.
nvd
CVE-2023-34056P4MEDIUMCVSS 4.3v5.xv4.x2023-10-25
CVE-2023-34056 [MEDIUM] CWE-922 CVE-2023-34056: vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-a vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.
nvd