VMware Security Updates – 25 October 2023

VMware has released security updates to fix multiple vulnerabilities affecting VMware vCenter Server, and VMware Cloud Foundation.

The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, execute arbitrary code, and gain access to the affected system by sending specially crafted requests.

Sample of the addressed vulnerabilities:

VMware vCenter Server Out-of-Bounds Write Vulnerability (CVE-2023-34048):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

Affected products:

  • VMware vCenter Server 7.0, 8.0.
  • VMware Cloud Foundation (VMware vCenter Server) 4.x, 5.x.
Vulnerabilities
  • CVE-2023-34048
  • CVE-2023-34056
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

VMware Security Advisory

References