First published: Thu Jun 22 2023(Updated: )
The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts vCenter Server.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vCenter Server | <7.0 | |
VMware vCenter Server | =7.0 | |
VMware vCenter Server | =7.0-a | |
VMware vCenter Server | =7.0-b | |
VMware vCenter Server | =7.0-c | |
VMware vCenter Server | =7.0-d | |
VMware vCenter Server | =7.0-update1 | |
VMware vCenter Server | =7.0-update1a | |
VMware vCenter Server | =7.0-update1c | |
VMware vCenter Server | =7.0-update1d | |
VMware vCenter Server | =7.0-update2 | |
VMware vCenter Server | =7.0-update2a | |
VMware vCenter Server | =7.0-update2b | |
VMware vCenter Server | =7.0-update2c | |
VMware vCenter Server | =7.0-update2d | |
VMware vCenter Server | =7.0-update3 | |
VMware vCenter Server | =7.0-update3a | |
VMware vCenter Server | =7.0-update3c | |
VMware vCenter Server | =7.0-update3d | |
VMware vCenter Server | =7.0-update3e | |
VMware vCenter Server | =7.0-update3f | |
VMware vCenter Server | =7.0-update3g | |
VMware vCenter Server | =7.0-update3h | |
VMware vCenter Server | =7.0-update3i | |
VMware vCenter Server | =7.0-update3j | |
VMware vCenter Server | =7.0-update3k | |
VMware vCenter Server | =7.0-update3l | |
VMware vCenter Server | =8.0 | |
VMware vCenter Server | =8.0-a | |
VMware vCenter Server | =8.0-b | |
VMware vCenter Server | =8.0-c | |
VMware vCenter Server | =8.0-update1 | |
VMware vCenter Server | =8.0-update1a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20892 is a heap overflow vulnerability in the vCenter Server due to the usage of uninitialized memory in the implementation of the DCERPC protocol.
CVE-2023-20892 is rated as critical with a severity score of 9.8.
VMware vCenter Server versions 7.0 and 8.0 are affected by CVE-2023-20892.
A malicious actor with network access to vCenter Server can exploit the heap overflow vulnerability to execute arbitrary code on the underlying operating system.
You can find more information about CVE-2023-20892 at the following references: [Talos Intelligence](https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1801), [VMware Security Advisories](https://www.vmware.com/security/advisories/VMSA-2023-0014.html).