CISA Known Exploited Vulnerability (KEV)
VMware vCenter Server Out-of-Bounds Write Vulnerability
January 22, 2024
February 12, 2024
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-787 |
Out-of-bounds Write |