QID 216318

Date Published: 2023-11-22

QID 216318: VMware vCenter Server 6.7 Update 6.7U3T (VMSA-2023-0023)

VMware vCenter Server is a server management solution that helps IT admins manage virtualized hosts and virtual machines in enterprise environments via a single console.

Affected Versions:
VMware vCenter Server Virtual Appliance 6.7 prior to 22509751.

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware vCenter Server with build version using web service present on the target.

A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Refer to VMware advisory VMSA-2023-0023 for more information.

    CVEs related to QID 216318

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2023-0023 URL Logo www.vmware.com/security/advisories/VMSA-2023-0023.html