CVE-2023-34048 — exposed on the internet
CVE-2023-34048: Vulnerability in VMware VMware vCenter Server
Internet exposure observed by OffSeq scans · last 30 days
Found on 1 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.
About CVE-2023-34048
CVE-2023-34048 is a critical out-of-bounds write vulnerability in VMware vCenter Server versions 7.0 and 8.0, specifically in the DCERPC protocol implementation. This flaw allows a remote attacker with network access to the vCenter Server to trigger memory corruption that can lead to remote code execution without requiring authentication or user interaction. The vulnerability has a CVSS score of 9.8, indicating a severe risk to confidentiality, integrity, and availability. Although no known exploits are currently reported in the wild, the ease of exploitation and the critical nature of vCenter Server in enterprise environments make this a significant threat. European organizations relying on VMware vCenter for virtualization management are at high risk, especially in countries with large enterprise IT infrastructures. Immediate patching or mitigation is essential to prevent potential compromise. Defenders should prioritize network segmentation, restrict access to vCenter Server, and monitor for suspicious activity related to DCERPC traffic.
Vendor: VMwareCWE-787
OffSeq internet scanning found CVE-2023-34048 on 1 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.
Exposed-host countries
Exposed via
vmware