CVE-2023-34048

VMware vCenter Server Out-of-Bounds Write Vulnerability

Basic Information

CVE State
PUBLISHED
Reserved Date
May 25, 2023
Published Date
October 25, 2023
Last Updated
August 19, 2024
Vendor
VMware
Product
VMware vCenter Server, VMware Cloud Foundation (VMware vCenter Server)
Description
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2024-01-22 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2024-01-22 00:00:00 UTC