• News/
  • https://www.bleepingcomputer.com/news/security/vmware-confirms-critical-vcenter-flaw-now-exploited-in-attacks/

VMware confirms critical vCenter flaw now exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 19, 2024
·
Updated

VMware has confirmed that a critical vCenter Server remote code execution vulnerability patched in October is now under active exploitation. vCenter Server is a management platform for VMware vSphere environments that helps administrators manage ESX and ESXi servers and virtual machines (VMs). "VMware has confirmed that exploitation of CVE-2023-34048 has occurred in the wild," the company said in an update added to the original advisory this week. The vulnerability was reported by Trend Micro vulnerability researcher Grigory Dorodnov and is caused by an out-of-bounds write weakness in vCenter's DCE/RPC protocol implementation. Attackers can exploit it remotely in low-complexity attacks with high confidentiality, integrity, and availability impact that don't require authentication or user interaction. Due to its critical nature, VMware has also issued security patches for multiple end-of-life products without active support. Network access brokers like to take over VMware servers and then sell on cybercrime forums to ransomware gangs for easy access to corporate networks. Many ransomware groups (like Royal, Black Basta, LockBit, and, more recently, RTM Locker, Qilin, ESXiArgs, Monti, and Akira) are now known for directly targeting the victims' VMware ESXi servers to steal and encrypt their files and demand huge ransoms. According to Shodan data, more than 2,000 VMware Center servers are currently exposed online, potentially vulnerable to attacks and exposing corporate network...

Read full article

Affected Software

1 affected component
VMware vCenter Server
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical remote code execution vulnerability in VMware vCenter Server that is being actively exploited.

2

What security implications are discussed in the article?

The article highlights the risk of unauthorized access and system compromise due to the exploited vulnerability in vCenter Server.

3

What products or software are affected?

The affected software identified in the article is VMware vCenter Server.

4

When was the vulnerability patched?

The vulnerability was patched in October before being detected in active exploitation.

5

What should users of vCenter Server do in response to the vulnerability?

Users of vCenter Server are advised to apply the latest patches and implement security measures to mitigate exploitation risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203