CVE-2023-20894: Critical severity vmware vcenter vulnerability
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-20894?
CVE-2023-20894 is an out-of-bounds write vulnerability in the implementation of the DCERPC protocol in VMware vCenter Server.
How severe is CVE-2023-20894?
CVE-2023-20894 has a severity rating of 9.8, which is classified as critical.
What software is affected by CVE-2023-20894?
VMware vCenter Server versions 7.0 and 8.0 are affected by CVE-2023-20894.
How can I fix CVE-2023-20894?
Upgrade to a patched version of VMware vCenter Server as recommended by VMware's security advisory.
Where can I find more information about CVE-2023-20894?
You can find more information about CVE-2023-20894 in Talos Intelligence's vulnerability report and VMware's security advisory.