CVE-2023-20894: exploitation status and patch state
CVE-2023-20894 · CVSS 8.1 HIGH · EPSS 34%
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.
Is CVE-2023-20894 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 34%.
Public exploit code: none found in monitored sources.