CVE-2023-34048
VMware vCenter Server, VMware Cloud Foundation (VMware vCenter Server), vmware cloud_foundation
Published 25 Oct 2023 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 22 Jan 2024, with a remediation deadline of 12 Feb 2024 for US federal agencies.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.
References
- www.vmware.com/security/advisories/VMSA-2023-0023.html · Vendor Advisory
- www.vicarius.io/vsociety/posts/understanding-cve-2023-34048-a-zero-day-out-of-bound-write-in-vcenter-server · Exploit, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-34048 · US Government Resource