Junglewise Threat Intelligence

CVE-2023-34048: VMware vCenter Server Out-of-Bounds Write Vulnerability

CVE-2023-34048 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-01-22

Technologies: Broadcom vCenter Server, VMware Cloud Foundation. Vendors: VMware, Broadcom.

Executive brief

VMware vCenter Server contains an out-of-bounds write vulnerability in its implementation of the DCERPC protocol. A remote attacker with network access can exploit this flaw to achieve remote code execution.

Affected products

  • VMware vCenter Server 4.0 through 5.5, 7.0, 8.0

Timeline

  • 2023-10-25: disclosed: NVD Published Date
  • 2024-01-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-01-22: exploited: Reported as exploited in the wild

Related threats