CVE-2023-20893

HIGH

Vmware Vcenter Server < 7.0 - Use After Free

Title source: rule

Description

The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.

Scores

CVSS v3 8.1
EPSS 0.0233
EPSS Percentile 84.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-416
Status published

Affected Products (33)

vmware/vcenter_server < 7.0
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
... and 18 more

Timeline

Published Jun 22, 2023
Tracked Since Feb 18, 2026