CVE-2023-20893

HIGH

VMware vCenter Server - Use-After-Free in DCERPC Protocol Implementation

Title source: llm
STIX 2.1

Description

The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.

Scores

CVSS v3 8.1
EPSS 0.0334
EPSS Percentile 87.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (3)
vmware/vcenter_server 7.0 (26 CPE variants)
vmware/vcenter_server 8.0 (6 CPE variants)
vmware/vcenter_server < 7.0
Published Jun 22, 2023
Tracked Since Feb 18, 2026