VDB

CVE-2023-34048

CVE-2023-34048 PUBLISHED KEV

------------ On October 24, 2023 VMware released a Critical security advisory, VMSA-2023-0023, addressing security vulnerabilities found and resolved in VMware vCenter Server, which is present in VMware vSphere and Cloud Foundation products. The VMSA will always be the source of truth for what products & versions are affected, the workarounds, and proper patches to keep your organization secure. This document is a corollary to the advisory and includes self-service information to help you and your organization decide how to respond. These vulnerabilities are memory management and corruption issues which can be used as a remote code execution attack against VMware vCenter Server services. You are affected by this vulnerability if you are running any version of vSphere except the latest updates for vSphere 6.5, 6.7, 7.0, or 8.0. Please consult the VMSA itself for the definitive list of affected versions. If you have a question about whether you are affected it is likely that you are, and should take action immediately.

EPSS 99.43% · 99.9th percentile

Risk Scores

EPSS Score
99.43%
99.9th percentile

Timeline

  • Oct 24, 2023 CVE Published
  • Oct 25, 2023 EPSS Score
  • Oct 25, 2023 PoC Published
  • Oct 25, 2023 PoC Published
  • Oct 25, 2023 PoC Published
  • Oct 25, 2023 PoC Published
  • Oct 25, 2023 PoC Published
  • Oct 25, 2023 PoC Published
  • Oct 26, 2023 PoC Published
  • Oct 26, 2023 PoC Published
  • Nov 11, 2023 PoC Published
  • Nov 15, 2023 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›