CVE-2023-20892: exploitation status and patch state
CVE-2023-20892 · CVSS 8.1 HIGH · EPSS 2%
The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts vCenter Server.
Is CVE-2023-20892 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 2%.
Public exploit code: none found in monitored sources.