EXPOSURES › CVE-2023-34048
CVE-2023-34048
HIGH ⌖ ON CISA KEV · EXPLOITEDVMware vCenter Server was exploited in the wild via CVE-2023-34048, enabling remote code execution through an out-of-bounds write in the DCERPC protocol.
This vulnerability allows remote attackers to execute arbitrary code on vCenter Server instances, posing a severe risk to defense-industrial-base organizations relying on VMware infrastructure for mission-critical operations. The fact that this vulnerability is actively exploited in the wild and linked to ransomware campaigns means organizations must prioritize patching immediately to prevent unauthorized access and data exfiltration. DIB orgs should verify their vCenter versions against the latest security advisories and ensure all systems are patched before the next maintenance window.
Shame score — Active exploitation in the wild combined with remote code execution capabilities creates a high-risk scenario for defense contractors and government agencies.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |