PT-2023-6424 · Vmware · Vmware Vcenter Server+1

Grigory Dorodnov

·

Published

2023-10-24

·

Updated

2026-03-07

·

CVE-2023-34048

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VMware vCenter Server versions prior to October 2023
Description VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability, potentially leading to remote code execution. This vulnerability has been actively exploited by the Chinese espionage group UNC3886 since late 2021, targeting defense, government, telecom, and technology sectors in the US and APJ regions. The vulnerability allows attackers to compromise hypervisors, install HTTP backdoors, access guests using PowerCLI, and run unregistered VMs via the VMware CLI. Hundreds of potentially vulnerable instances have been identified globally.
Recommendations Update VMware vCenter Server to the latest version available as of October 2023.

Exploit

Fix

RCE

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07140
CVE-2023-34048
ZDI-23-1590

Affected Products

Vmware Vcenter
Vmware Vcenter Server