id: CVE-2023-34048 info: name: VMware vCenter Server - Out-of-Bounds Write author: ritikchaddha severity: critical description: | vCenter Server contains an out-of-bounds write caused by a vulnerability in the DCERPC protocol implementation. A malicious actor with network access can trigger remote code execution on vCenter Server. impact: | Unauthenticated attackers with network access can exploit the out-of-bounds write vulnerability in the DCERPC protocol to execute arbitrary code on vCenter Server, potentially compromising the entire VMware virtualization infrastructure. remediation: | Apply VMware security patches from VMSA-2023-0023 for vCenter Server versions 4.0-5.5 and 7.0-8.0 that fix the DCERPC protocol vulnerability. reference: - https://www.vicarius.io/vsociety/posts/understanding-cve-2023-34048-a-zero-day-out-of-bound-write-in-vcenter-server - https://www.vmware.com/security/advisories/VMSA-2023-0023.html - https://nvd.nist.gov/vuln/detail/CVE-2023-34048 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2023-34048 epss-score: 0.99428 epss-percentile: 0.99938 cwe-id: CWE-787 metadata: verified: true max-request: 2 vendor: vmware product: vcenter_server shodan-query: title:"VMware VCenter" fofa-query: title="VMware VCenter" tags: cve,cve2023,vmware,vcenter,rce,kev,vkev,passive http: - raw: - | GET /en/welcomeRes.js HTTP/1.1 Host: {{Hostname}} - | POST /sdk/ HTTP/1.1 Host: {{Hostname}} 00000001-00000001 <_this xsi:type="ManagedObjectReference" type="ServiceInstance">ServiceInstance stop-at-first-match: true matchers-condition: and matchers: - type: word part: body words: - "VMware vCenter" - "VirtualCenter" case-insensitive: true - type: status status: - 200 - type: dsl dsl: - compare_versions(version, '>= 4.0', '<= 5.5') - compare_versions(version, '>= 7.0', '<= 8.0') extractors: - type: regex name: version part: body group: 1 regex: - 'vCenter Converter Standalone ([0-9.]+)' - "(.*?)" # digest: 490a0046304402206ce4f8c15c2d7f3c14217f4ae5f0175c3c6cda82a3ea642ce764c3987e6bf7e50220475172cb25300935a82b82dc46d9a2cabffa6a54ff582c7ce72d63adb06005d9:922c64590222798bb761d5b6d8e72950