VMware vCenter Server heap-overflow vulnerability
CVE-2023-20892
8.1HIGH
Key Information:
- Vendor
- Vmware
- Vendor
- CVE Published:
- 22 June 2023
Summary
The vCenter Server is vulnerable to a heap overflow caused by the use of uninitialized memory within the DCERPC protocol implementation. This flaw allows a malicious actor with network access to exploit the vulnerability, potentially executing arbitrary code on the operating system hosting the vCenter Server. Organizations are urged to implement immediate security measures to mitigate the risks associated with this vulnerability.
Affected Version(s)
VMware Cloud Foundation (vCenter Server) Windows 5.x < 7.0 U3m, 8.0 U1b
VMware Cloud Foundation (vCenter Server) Windows 4.x < 7.0 U3m, 8.0 U1b
VMware vCenter Server (vCenter Server) Windows 8.0 < 8.0 U1b
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved