Database/Kernel, userspace & hypervisor
VMware vCenter: Out-of-bounds write in the DCERPC implementation - unauthenticated remote code execution
CVSS 9.8CVE-2023-34048Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Out-of-bounds write in the DCERPC implementation - unauthenticated remote code execution; exploited as a zero-day by UNC3886 since at least 2021 [KEV]
Who can reach it
Unauthenticated network to the management plane
What to do
vCenter patch + service restart. Assume compromise on any vCenter that was internet- or tenant-reachable before Oct 2023
References
Related entries
- VMware vCenter: Heap overflow in the DCERPC implementation - unauthenticated remote code execution on vCenterCVE-2024-37079 · VMware vCenterCritical
- VMware vCenter: Heap overflow in DCERPC - unauthenticated remote code execution on vCenterCVE-2024-38812 · VMware vCenterCritical
- VMware vCenter: Privilege escalation to root on vCenter via a crafted network packetCVE-2024-38813 · VMware vCenterHigh
- OpenSSH (ssh-agent): Remote code execution in ssh-agent PKCS#11 support when agent forwarding reaches a hostile hostCVE-2023-38408 · OpenSSH (ssh-agent)Critical
- Linux kernel NVMe target core (nvmet_req_complete submission-queue dereference): Nvmet_req_complete() dereferenced reqCVE-2023-53116 · Linux kernel NVMe target core (nvmet_req_complete submission-queue dereference)Critical
- Linux kernel (net/smc): When an incoming connection tries SMC-Rv2 and device setup fails, the listener does not resetCVE-2023-53382 · Linux kernel (net/smc)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.