CVE-2023-20892: VMware vCenter Server heap-overflow vulnerability
The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts vCenter Server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-20892?
CVE-2023-20892 is a heap overflow vulnerability in the vCenter Server due to the usage of uninitialized memory in the implementation of the DCERPC protocol.
How severe is CVE-2023-20892?
CVE-2023-20892 is rated as critical with a severity score of 9.8.
What software is affected by CVE-2023-20892?
VMware vCenter Server versions 7.0 and 8.0 are affected by CVE-2023-20892.
How can a malicious actor exploit CVE-2023-20892?
A malicious actor with network access to vCenter Server can exploit the heap overflow vulnerability to execute arbitrary code on the underlying operating system.
Where can I find more information about CVE-2023-20892?
You can find more information about CVE-2023-20892 at the following references: [Talos Intelligence](https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1801), [VMware Security Advisories](https://www.vmware.com/security/advisories/VMSA-2023-0014.html).