VMware patches critical vulnerability in vCenter Server (CVE-2023-34048)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-20887 | Unauthenticated Command Injection RCE in VMware Aria Operations for Networks VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection flaw (CWE-77) that allows an attacker with network access to the appliance to run arbitrary operating-system commands. Because the attack requires no authentication, privileges, or user interaction (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), any party able to reach the product's network interface can trigger it, gaining remote code execution with high impact on confidentiality, integrity, and availability. Any organization running the product is affected, with internet-facing deployments at the greatest risk. Exploitation is confirmed in the wild — CISA added the flaw to the KEV catalog on 2023-06-22, a public proof-of-concept exploit is available, and EPSS puts the 30-day exploitation probability at 98.3% (top percentile). Ransomware use is currently unknown. Do: Apply the vendor's patched update to all Aria Operations for Networks deployments as soon as possible — this is also CISA's required KEV action (apply updates per vendor instructions); verify the installed build against VMware's advisory for affected ranges. Until patching is complete, restrict network access to the appliance (firewall rules, VPN, or management-segment isolation), prioritizing any instance reachable from the internet since no authentication is required to exploit. Hunt for indicators of command injection exploitation, as in-the-wild exploitation has been confirmed. | 9.8 | 98% | KEV PoC |
| moderate≈10,000+ appliance deployments worldwide (low tens of thousands of appliance nodes); only a small fraction, likely hundreds to low thousands of instances, are… | |
| CVE-2023-34048 +1 in the same advisory: …34056 | Unauthenticated Out-of-Bounds Write RCE in VMware vCenter Server VMware vCenter Server contains an out-of-bounds write vulnerability (CWE-787) in its implementation of the DCERPC protocol. A remote, unauthenticated attacker with network access to vCenter Server can send crafted DCERPC traffic that corrupts memory, potentially leading to remote code execution on the vCenter appliance. Because vCenter is the central management plane for VMware vSphere environments, full compromise of it hands attackers a high-value foothold for lateral movement, consistent with the critical 9.8 CVSS score. Any organization running an affected VMware vCenter Server release is exposed (exact version ranges per VMware's advisory, including VMware Cloud Foundation deployments that bundle vCenter). Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2024-01-22, a public PoC is available, news reports describe China-linked APT UNC3886 exploiting it as a zero-day, and EPSS estimates a 99.4% probability of exploitation within 30 days. Do: Immediately upgrade vCenter Server — and VMware Cloud Foundation deployments that bundle it — to the patched builds identified in VMware's advisory, prioritizing internet-facing instances; if patching must wait, restrict network access to the vCenter management interface as the CISA KEV required action permits. Because exploitation is confirmed in the wild including by an APT, also hunt for signs of compromise such as unexpected processes or authentication activity on vCenter hosts and managed ESXi estate. | 9.8 group max | 99% | KEV PoC |
| mass≈100,000+ vCenter Server deployments globally (tens of thousands directly internet-exposed per public scans, far more reachable on internal networks) | |
| CVE-2023-34051 | VMware Aria Operations for Logs contains an authentication bypass vulnerability. VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. NVD description · AI analysis pending | 9.8 | 45% |
| — |
Full article402 words · extracted from helpnetsecurity.com · click to collapse
VMware has fixed a critical out-of-bounds write vulnerability (CVE-2023-34048) and a moderate-severity information disclosure flaw (CVE-2023-34056) in vCenter Server, its popular server management software.
About CVE-2023-34048 and CVE-2023-34056
CVE-2023-34048 allows an attacker with network access to a vulnerable vCenter Server virtual appliance to trigger an out-of-bounds write that can lead to remote code execution.
It has been reported by Grigory Dorodnov of Trend Micro Zero Day Initiative and there are no indications of it being exploited in the wild.
A second vulnerability (CVE-2023-34056) in the VMware vCenter Server has been reported by Oleg Moshkov of Deiteriy Lab OÜ. It is a partial information disclosure vulnerability that could allow an attacker with non-administrative privileges to access unauthorized data.
Both vulnerabilities also affect products that contain vCenter Server, i.e., vSphere and Cloud Foundation (VCF).
No workarounds are available, so users are urged to update to the fixed versions as soon as possible.
“Due to the critical severity of this vulnerability and lack of workaround VMware has made a patch generally available for vCenter Server 6.7U3, 6.5U3, and VCF 3.x. For the same reasons, VMware has made additional patches available for vCenter Server 8.0U1,” the company said.
Asynchronous vCenter Server patches for VCF 5.x and 4.x deployments are also available.
“There may be other mitigations available in your organization depending on your security posture, defense-in-depth strategies, and configurations of perimeter firewalls and appliance firewalls. All organizations must decide for themselves whether to rely on those protections,” the company added.
While VMware went public with the vulnerabilities today, some of the security updates containing the fixes have been released in late September. If you’re a vCenter Server admin and generally quick to update, your installations might already be safe from exploitation.
Vulnerable VMware products and PoCs
In June, a critical pre-authentication command injection vulnerability (CVE-2023-20887) in VMware Aria Operations for Network was observed being exploited in the wild.
On Monday, the company confirmed that a proof of concept exploit for a high-severity authentication bypass vulnerability (CVE-2023-34051) in Aria Operations for Logs, its popular log storage and analysis tool, had been published.
UPDATE (January 19, 2024, 08:42 a.m. ET):
“VMware has confirmed that exploitation of CVE-2023-34048 has occurred in the wild,” the company noted in the updated security advisory.
UPDATE (January 22, 2024, 05:00 a.m. ET):
Mandiant says that a highly advanced China-backed espionage group “has been exploiting CVE-2023-34048 as far back as late 2021.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/10/25/cve-2023-34048/