Out-of-bounds write in vCenter Server - CVE-2023-34048

 

Out-of-bounds write in vCenter Server - CVE-2023-34048

Published: October 25, 2023 / Updated: September 4, 2024


Vulnerability identifier: #VU82353
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34048
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error within the DCERPC protocol implementation. A remote non-authenticated attacker can send a specially crafted RPC request to the vCenter Server, trigger an out-of-bounds write and execute arbitrary code on the target system.

Note, the vulnerability is being actively exploited in the wild since late 2021.


Affected software

vCenter Server
PowerFlex Appliance
PowerFlex rack
IBM Cloud Pak System
Dell EMC VxRail Appliance

How to mitigate CVE-2023-34048

Install updates from vendor's website.

vCenter Server - addressed in versions 7.0 U3o, 8.0 U1d, 8.0 U2
PowerFlex Appliance - update to IC-45.373.01
IBM Cloud Pak System - update to 2.3.3.6 iFix 2
PowerFlex rack - update to 3.7.3.1
Dell EMC VxRail Appliance - update to 8.0.120

External References

Related Security Bulletins