Lucene search

K
cvelistVmwareCVELIST:CVE-2023-20893
HistoryJun 22, 2023 - 11:52 a.m.

CVE-2023-20893

2023-06-2211:52:32
vmware
www.cve.org
vmware
vcenter server
vulnerability
cve-2023-20893
use-after-free
dcerpc protocol
network access
arbitrary code
operating system

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

9.9 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.7%

The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows",
      "Linux",
      "Android",
      "x86",
      "ARM",
      "64 bit",
      "32 bit",
      "MacOS",
      "iOS"
    ],
    "product": "VMware vCenter Server (vCenter Server)",
    "vendor": "VMware",
    "versions": [
      {
        "lessThan": "8.0 U1b",
        "status": "affected",
        "version": "8.0",
        "versionType": "8.0 u1b"
      },
      {
        "lessThan": "7.0 u3m",
        "status": "affected",
        "version": "7.0",
        "versionType": "7.0 u3m"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows",
      "Linux",
      "Android",
      "64 bit",
      "32 bit",
      "ARM",
      "x86",
      "MacOS",
      "iOS"
    ],
    "product": "VMware Cloud Foundation (vCenter Server)",
    "vendor": "VMware",
    "versions": [
      {
        "lessThan": "7.0 U3m, 8.0 U1b",
        "status": "affected",
        "version": "5.x",
        "versionType": "7.0 U3m, 8.0 U1b"
      },
      {
        "lessThan": "7.0 U3m, 8.0 U1b",
        "status": "affected",
        "version": "4.x",
        "versionType": "7.0 U3m, 8.0 U1b"
      }
    ]
  }
]

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

9.9 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.7%

Related for CVELIST:CVE-2023-20893