CVE-2023-20895: exploitation status and patch state
CVE-2023-20895 · CVSS 8.1 HIGH · EPSS 1%
The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.
Is CVE-2023-20895 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 1%.
Public exploit code: none found in monitored sources.