PT-2023-6424 · Vmware · Vmware Vcenter Server+1
Grigory Dorodnov
·
Publicado
2023-10-24
·
Atualizado
2026-03-07
·
CVE-2023-34048
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VMware vCenter Server versions prior to October 2023
Description
VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability, potentially leading to remote code execution. This vulnerability has been actively exploited by the Chinese espionage group UNC3886 since late 2021, targeting defense, government, telecom, and technology sectors in the US and APJ regions. The vulnerability allows attackers to compromise hypervisors, install HTTP backdoors, access guests using PowerCLI, and run unregistered VMs via the VMware CLI. Hundreds of potentially vulnerable instances have been identified globally.
Recommendations
Update VMware vCenter Server to the latest version available as of October 2023.
Exploit
Correção
RCE
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Vmware Vcenter
Vmware Vcenter Server