CVE-2023-34048: VMware vCenter Server Out-of-Bounds Write Vulnerability
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.
Other sources
VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of VMware vCenter Server if vendor mitigations are unavailable.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-34048?
CVE-2023-34048 is a vulnerability in vCenter Server that allows a malicious actor to trigger an out-of-bounds write potentially leading to remote code execution.
What is the severity of CVE-2023-34048?
CVE-2023-34048 has a severity rating of 9.8, which means it is considered critical.
How does CVE-2023-34048 affect vCenter Server?
CVE-2023-34048 affects vCenter Server by exploiting an out-of-bounds write vulnerability in the implementation of the DCERPC protocol.
What versions of vCenter Server are affected by CVE-2023-34048?
CVE-2023-34048 affects VMware vCenter Server versions 4.0 to 5.5, and versions 7.0 to 8.0.
How can I fix CVE-2023-34048?
To fix CVE-2023-34048, it is recommended to apply the necessary updates or patches provided by VMware. Please refer to the official VMware security advisory for specific instructions.