CVE-2023-34048
VMware vCenter Server Out-of-Bounds Write Vulnerability
Record summary
CVE-2023-34048 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template. CISA lists CVE-2023-34048 in KEV.
Description
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.
Exploitation context
Known exploitation
- CISA KEV
- Listed · Jan 22, 2024 · CISA
- VulnCheck KEV
- Listed · Jan 17, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 11, 2024 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
VMware Cloud Foundation (VMware vCenter Server)Browse VMware / VMware Cloud Foundation (VMware vCenter Server)Default status: unaffected | CVE List | 5.x | affected |
| 4.x | affected | ||
VMware vCenter ServerBrowse VMware / VMware vCenter ServerDefault status: unaffected | CVE List | 8.0 to < 8.0U2 | affected |
| 7.0 to < 7.0U3o | affected | ||
vCenter ServerBrowse VMware / vCenter ServerDefault status: unknown | CISA, CVE List | 7.0 to < 7.0U3o | affected |
| 8.0 to < 8.0U2 | affected | ||
cloud_foundationBrowse vmware / cloud_foundationDefault status: unknown | CVE List | 4.0 to < KB88287 | affected |
| 5.0 to < KB88287 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALVMware vCenter Server - Out-of-Bounds WriteCVSS 9.8
vCenter Server contains an out-of-bounds write caused by a vulnerability in the DCERPC protocol implementation. A malicious actor with network access can trigger remote code execution on vCenter Server.
Impact
Unauthenticated attackers with network access can exploit the out-of-bounds write vulnerability in the DCERPC protocol to execute arbitrary code on vCenter Server, potentially compromising the entire VMware virtualization infrastructure.
Remediation
Apply VMware security patches from VMSA-2023-0023 for vCenter Server versions 4.0-5.5 and 7.0-8.0 that fix the DCERPC protocol vulnerability.
Source: ProjectDiscovery