Database/Kernel, userspace & hypervisor
VMware vCenter: Out-of-bounds write in the DCERPC implementation - unauthenticated remote code execution
CVE-2023-34048Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Out-of-bounds write in the DCERPC implementation - unauthenticated remote code execution; exploited as a zero-day by UNC3886 since at least 2021 [KEV]
Who can reach it
Unauthenticated network to the management plane
What to do
vCenter patch + service restart. Assume compromise on any vCenter that was internet- or tenant-reachable before Oct 2023
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.