CVE-2023-20893: Use After Free
The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20893?
The severity of CVE-2023-20893 is critical.
What is the affected software for CVE-2023-20893?
The affected software for CVE-2023-20893 is VMware vCenter Server versions up to and including 7.0.
How can a malicious actor exploit CVE-2023-20893?
A malicious actor with network access to vCenter Server can exploit CVE-2023-20893 to execute arbitrary code on the underlying operating system.
Are there any patches or updates available for CVE-2023-20893?
Yes, VMware has released security advisories with patches to address CVE-2023-20893. It is recommended to update to the latest version of VMware vCenter Server.
Where can I find more information about CVE-2023-20893?
You can find more information about CVE-2023-20893 in the vulnerability reports by Talos Intelligence and the security advisories by VMware.