Back to Labs
Security Advisory

CVE-2023-34048

About

vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.

Weakness (CWE):CWE-787

Rainforest analyst review

vCenter Server has an out-of-bounds write in its implementation of the DCERPC protocol. A network-positioned attacker sends crafted DCERPC traffic that overflows a buffer, corrupting memory in a way that can be steered toward remote code execution. No authentication is required; reaching the affected service on the network is enough, and success means running code on the appliance that manages the virtualization estate.

vCenter is the control plane for VMware vSphere, governing the ESXi hosts and virtual machines that run much of enterprise infrastructure, so code execution there is a master key to the datacenter. Mandiant later attributed exploitation of this bug to the espionage group tracked as UNC3886, which used it as far back as 2021 to move against ESXi hosts, and it is on CISA's KEV list. Patch to the fixed vCenter releases promptly, including the backports VMware issued for end-of-life 6.x lines. Because it was exploited quietly for years before disclosure, restrict network access to vCenter's management services and hunt for signs of prior compromise, not just apply the update.

References

Related CVEs

Frequently asked questions

What is CVE-2023-34048?

vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.

How severe is CVE-2023-34048?

CVE-2023-34048 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2023-34048 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2023-34048?

Public advisories list the following as affected: vcenter server. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2023-34048?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email