CVE-2023-20895: Critical severity vmware vcenter vulnerability
The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-20895?
CVE-2023-20895 is a memory corruption vulnerability in the implementation of the DCERPC protocol in VMware vCenter Server.
How severe is the vulnerability CVE-2023-20895?
The severity of CVE-2023-20895 is critical with a CVSS score of 9.8.
What software is affected by CVE-2023-20895?
VMware vCenter Server versions 7.0 and 8.0 are affected by CVE-2023-20895.
How can a malicious actor exploit CVE-2023-20895?
A malicious actor with network access to vCenter Server can trigger a memory corruption vulnerability to bypass authentication.
Where can I find more information about CVE-2023-20895?
You can find more information about CVE-2023-20895 in the Talos Intelligence vulnerability report and the VMware security advisory.