vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.
Is CVE-2023-34048 exploited?
Listed in the CISA KEV catalog on 2024-01-22.
Federal remediation due 2024-02-12.
Past that date by 915 days.
EPSS puts exploitation in the next 30 days at 99%.
Public exploit code: none found in monitored sources.