ZDI-23-1590: VMware vCenter Server Appliance DCE/RPC Protocol Out-Of-Bounds Write Remote Code Execution Vulnerability
Published Nov 6, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VMware vCenter Server Appliance. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2023-34048.
Affected Software
1 affected component
VMware vCenter Server Appliance
Event History
Nov 6, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1590?
The severity of ZDI-23-1590 is rated at 9.8 on the CVSS scale.
2
How do I fix ZDI-23-1590?
To fix ZDI-23-1590, apply the latest security patches provided by VMware for the vCenter Server Appliance.
3
Who is affected by ZDI-23-1590?
Organizations using VMware vCenter Server Appliance are affected by ZDI-23-1590.
4
Can ZDI-23-1590 be exploited without authentication?
Yes, ZDI-23-1590 can be exploited without any authentication.
5
What kind of vulnerability is ZDI-23-1590?
ZDI-23-1590 is a remote code execution vulnerability.