January 22, 2024 · Applied Cybernetics Group
CVE-2023-34048 — VMware vCenter Server
VMware vCenter Server Out-of-Bounds Write Vulnerability
- Added to KEV
2024-01-22- Federal due date
2024-02-12- Vendor
- VMware
- Product
- vCenter Server
- EPSS
- 99.8th percentile (score 0.932, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2023-34048
CISA short description
VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.