Out-of-Bounds Write Vulnerability in VMware vCenter Server
CVE-2023-20894

8.1HIGH

Key Information:

Summary

The VMware vCenter Server has an out-of-bounds write vulnerability arising from the implementation of the DCERPC protocol. This security flaw allows a remote attacker with network access to the vCenter Server to exploit the vulnerability by crafting and sending a malicious packet. Successfully triggering the out-of-bounds write can lead to memory corruption, which may compromise the integrity and availability of vCenter Server services. Organizations utilizing affected versions should prioritize updating to mitigate potential security threats.

Affected Version(s)

VMware Cloud Foundation (vCenter Server) Windows 5.x < 7.0 U3m, 8.0 U1b

VMware Cloud Foundation (vCenter Server) Windows 4.x < 7.0 U3m, 8.0 U1b

VMware vCenter Server (vCenter Server) Windows 8.0 < 8.0 U1b

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.