VMware vCenter Server Out-of-Bounds Write Vulnerability
ID: 8a930b4e-20a5-5493-9a5b-0206b1776983
STIX ID: report--8a930b4e-20a5-5493-9a5b-0206b1776983
Feed Name: Kudelski Security
VMware has released updates to address CVE-2023-34048, a critical (CVSS 9.8) out-of-bounds write in vCenter Server's DCE/RPC implementation that can enable remote code execution; affected versions include vCenter Server 7.0 & 8.0 and VMware Cloud Foundation 4.x/5.x (unsupported 6.x also affected), no in-product workaround exists, network access to ports 2012/tcp, 2014/tcp and 2020/tcp are relevant, and administrators are advised to apply the vendor updates listed to remediate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
