← Back to browse · API

CVE-2023-20894

Severity
HIGH
CVSS
8.1
EPSS
0.33945
Risk score
44.28
CISA KEV
No
PoC
No
Published
2023-06-22
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2023-25065, GHSA-8X4H-JR9X-82RR
Products
VMware:VMware Cloud Foundation (vCenter Server) 4.x <7.0 U3m, 8.0 U1b, VMware:VMware Cloud Foundation (vCenter Server) 5.x <7.0 U3m, 8.0 U1b, VMware:VMware vCenter Server (vCenter Server) 7.0 <7.0 u3m, VMware:VMware vCenter Server (vCenter Server) 8.0 <8.0 U1b
Sources
euvd EUVD-2023-25065

Description

The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.

References