PT-2022-5017 · Vmware · Vcenter Server+1

Icewall

+1

·

Published

2022-10-06

·

Updated

2022-10-11

·

CVE-2022-31680

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vCenter Server (affected versions not specified)
Description The vCenter Server contains an unsafe deserialization vulnerability in the PSC (Platform services controller). A malicious actor with admin access on the vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server. The vulnerability is related to deficiencies in the deserialization mechanism, which can be exploited by a remote attacker to execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2022-06230
CVE-2022-31680

Affected Products

Vmware Vcenter
Vcenter Server