Executive brief
VMware vCenter Server contains an out-of-bounds write vulnerability in its implementation of the DCERPC protocol. A remote attacker with network access can exploit this flaw to achieve remote code execution.
Affected products
- VMware vCenter Server 4.0 through 5.5, 7.0, 8.0
Timeline
- 2023-10-25: disclosed: NVD Published Date
- 2024-01-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-01-22: exploited: Reported as exploited in the wild