Skip to content
COOEY

EXPOSURES › CVE-2023-34048

CVE-2023-34048

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-01-22 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-34048 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildransomwaresupply-chain

VMware vCenter Server was exploited in the wild via CVE-2023-34048, enabling remote code execution through an out-of-bounds write in the DCERPC protocol.

This vulnerability allows remote attackers to execute arbitrary code on vCenter Server instances, posing a severe risk to defense-industrial-base organizations relying on VMware infrastructure for mission-critical operations. The fact that this vulnerability is actively exploited in the wild and linked to ransomware campaigns means organizations must prioritize patching immediately to prevent unauthorized access and data exfiltration. DIB orgs should verify their vCenter versions against the latest security advisories and ensure all systems are patched before the next maintenance window.

Shame score — Active exploitation in the wild combined with remote code execution capabilities creates a high-risk scenario for defense contractors and government agencies.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized