VMware vCenter Server Vulnerabilities CVE-2023

Опубликовано: 19 Октябрь 2024
на канале: Lansweeper
1,126
1

VMware released security updates for vCenter Server in response to a number of memory corruption vulnerabilities. When exploited, the bugs could allow an attacker to execute code or bypass authentication. Use Lansweeper to find any vulnerable installs in your network ► http://lansweeper.com/vulnerability/4...

VMware's security advisory addresses 5 vulnerabilities in the implementation of the DCERPC protocol, 4 of which are in the important severity range with a CVSSv3 base score of 8.1. CVE-2023-20892 (a heap overflow vulnerability) and CVE-2023-20893 (a use-after-free vulnerability) could allow an attacker to execute arbitrary code on the underlying operating system that hosts vCenter Server. CVE-2023-20894 and CVE-2023-20895, respectively an out-of-bounds write and read vulnerability, could allow an attacker to bypass authentication through memory corruption. A fifth vulnerability, CVE-2023-20896, received a moderate severity rating of 5.9 and could lead to denial of service.

Start your free trial today ► https://www.lansweeper.com/download

Lansweeper enables you to manages your entire IT network, saving an incredible amount of time by automating key tasks. It features best in class fully automatic asset scanning and network inventory software, to keep you on top of your IT-environment.

Recommended by sysadmins all over the world, download your Lansweeper free trial today and start managing your IT assets the right way.

Useful Links
Website ► https://www.lansweeper.com/
Knowledgebase ► https://www.lansweeper.com/kb/
Forum ► https://www.lansweeper.com/forum/
Blog ► https://www.lansweeper.com/blog/

Let’s Connect
Facebook ►   / lansweeper.network.inventory  
Twitter ►   / lansweeper  
Linkedin ►   / lansweeper-bvba  
Contact ► [email protected]