logo

VMware vCenter Server Out-of-Bounds Write Vulnerability

ID: 8a930b4e-20a5-5493-9a5b-0206b1776983

STIX ID: report--8a930b4e-20a5-5493-9a5b-0206b1776983

Feed Name: Kudelski Security

Threat Score
75/100

Date Published: 2023-10-25

Date Updated: 2026-07-22

...
...

VMware has released updates to address CVE-2023-34048, a critical (CVSS 9.8) out-of-bounds write in vCenter Server's DCE/RPC implementation that can enable remote code execution; affected versions include vCenter Server 7.0 & 8.0 and VMware Cloud Foundation 4.x/5.x (unsupported 6.x also affected), no in-product workaround exists, network access to ports 2012/tcp, 2014/tcp and 2020/tcp are relevant, and administrators are advised to apply the vendor updates listed to remediate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.