CVE-2022-31680

CRITICAL

VMware vCenter Server - Remote Code Execution via Unsafe Deserialization in Platform Services Controller

Title source: llm
STIX 2.1

Description

The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.

Scores

CVSS v3 9.1
EPSS 0.0336
EPSS Percentile 87.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (2)
vmware/vcenter_server 6.5 (27 CPE variants)
vmware/vcenter_server < 6.5
Published Oct 07, 2022
Tracked Since Feb 18, 2026