CVE-2023-34056
------------ On October 24, 2023 VMware released a Critical security advisory, VMSA-2023-0023, addressing security vulnerabilities found and resolved in VMware vCenter Server, which is present in VMware vSphere and Cloud Foundation products. The VMSA will always be the source of truth for what products & versions are affected, the workarounds, and proper patches to keep your organization secure. This document is a corollary to the advisory and includes self-service information to help you and your organization decide how to respond. These vulnerabilities are memory management and corruption issues which can be used as a remote code execution attack against VMware vCenter Server services. You are affected by this vulnerability if you are running any version of vSphere except the latest updates for vSphere 6.5, 6.7, 7.0, or 8.0. Please consult the VMSA itself for the definitive list of affected versions. If you have a question about whether you are affected it is likely that you are, and should take action immediately.
EPSS 0.67% · 48.5th percentile
Risk Scores
Timeline
- Oct 24, 2023 CVE Published
- Oct 25, 2023 EPSS Score
- Oct 26, 2023 PoC Published
- Nov 25, 2023 EPSS Score
- Dec 26, 2023 EPSS Score
- Jan 18, 2024 CVE Updated
- Jan 26, 2024 EPSS Score
- Feb 26, 2024 EPSS Score
- Mar 28, 2024 EPSS Score
- Apr 28, 2024 EPSS Score
- May 29, 2024 EPSS Score
- Jun 29, 2024 EPSS Score