{"id":6458,"date":"2024-01-19T16:17:09","date_gmt":"2024-01-19T22:17:09","guid":{"rendered":"https:\/active-remote-code-execution-vulnerability-exploit-in-vmware\/"},"modified":"2024-10-17T17:48:03","modified_gmt":"2024-10-17T22:48:03","slug":"active-remote-code-execution-vulnerability-exploit-in-vmware","status":"publish","type":"post","link":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/","title":{"rendered":"Active remote code execution vulnerability exploit in VMware"},"content":{"rendered":"<p>In October 2023 a TrendMicro researcher had discovered and published details of a critical vulnerability in VMware, specifically, in VMware vSphere. This is a management platform for VMware environments, used to manage ESX and ESXi servers and virtual machines. The vulnerability, identified as CVE-2023-34048, arises from an out-of-bounds write weakness in vCenter&#8217;s DCE\/RPC protocol implementation and allows an unauthenticated attacker, by sending specially crafted remote requests, to execute arbitrary code, gaining full control over the platform, without the need for any user interaction. Cybolt had warned about this vulnerability through <a href=\"https:\/publicacion\/alerta-2023-06\/\">Alert 2023-06<\/a>. Recently, almost 3 months later, it has started to be seen that this vulnerability is being used in multiple attacks. Given the seriousness of the situation, VMware has released security patches even for products that have reached end of life without active support.   <\/p>\n<p id=\"ember48\" class=\"ember-view reader-content-blocks__paragraph\">Specifically, it has been reported that various actors are taking control of VMware servers and selling them on cybercrime forums to ransomware groups.<br \/>\nCurrently, many of the ransomware groups, such as Royal, Black Basta, LockBit, RTM Locker, Qilin, ESXiArgs, Monti and Akira, among others, have been noted for directly targeting victims&#8217; VMware ESXi servers to encrypt files and demand hefty ransoms. <\/p>\n<p id=\"ember49\" class=\"ember-view reader-content-blocks__paragraph\">We can visualize that there are more than 2,200 VMware Center servers currently exposed online, many of them also in Mexico, with a very high latent risk potential.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"wp-image-5808 aligncenter\" src=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/01\/Captura-de-pantalla-2024-01-19-190917-300x129.png\" alt=\"\" width=\"433\" height=\"186\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/01\/Captura-de-pantalla-2024-01-19-190917-300x129.png 300w, https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/01\/Captura-de-pantalla-2024-01-19-190917-1024x442.png 1024w, https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/01\/Captura-de-pantalla-2024-01-19-190917-768x331.png 768w, https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/01\/Captura-de-pantalla-2024-01-19-190917-1536x663.png 1536w, https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/01\/Captura-de-pantalla-2024-01-19-190917.png 1557w\" sizes=\"(max-width: 433px) 100vw, 433px\" \/><\/p>\n<p class=\"ember-view reader-content-blocks__paragraph\">In cases where, for some reason, patching is not possible immediately, as there is no effective mitigation, VMware recommends strictly controlling network perimeter access to vSphere management components.<br \/>\nIn the event that your organization has had the VMware vSphere interface exposed to the Internet, unpatched, you should consider that it is probably already compromised and therefore look for signs of compromise not only on the machine but in the rest of the network. <\/p>\n<p id=\"ember50\" class=\"ember-view reader-content-blocks__paragraph\">In addition, it is important to note the importance of tight control of network perimeter access for all management components and interfaces in vSphere, as well as related components such as networking and storage.<br \/>\nThe company warns about specific ports (2012\/TCP, 2014\/TCP and 2020\/TCP) linked to potential exploits in attacks targeting this vulnerability. <\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Sources:<\/p>\n<p><a href=\"https:\/publicacion\/alerta-2023-06\/\">Cybolt Alert 2023-06<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/vmware-confirms-critical-vcenter-flaw-now-exploited-in-attacks\/\">Bleeping Computer<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In October 2023 a TrendMicro researcher had discovered and published details of a critical vulnerability in VMware, specifically, in VMware vSphere. This is a management platform for VMware environments, used to manage ESX and ESXi servers and virtual machines. The vulnerability, identified as CVE-2023-34048, arises from an out-of-bounds write weakness in vCenter&#8217;s DCE\/RPC protocol implementation [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":6297,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[48],"tags":[],"class_list":["post-6458","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"In October 2023 a TrendMicro researcher had discovered and published details of a critical vulnerability in VMware, specifically, in VMware vSphere. This is a management platform for VMware environments, used to manage ESX and ESXi servers and virtual machines. The vulnerability, identified as CVE-2023-34048, arises from an out-of-bounds write weakness in vCenter&#039;s DCE\/RPC protocol implementation\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Gabriela Ratti\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Beacon Lab - CSIRT by Cybolt\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Active remote code execution vulnerability exploit in VMware - Beacon Lab\" \/>\n\t\t<meta property=\"og:description\" content=\"In October 2023 a TrendMicro researcher had discovered and published details of a critical vulnerability in VMware, specifically, in VMware vSphere. This is a management platform for VMware environments, used to manage ESX and ESXi servers and virtual machines. The vulnerability, identified as CVE-2023-34048, arises from an out-of-bounds write weakness in vCenter&#039;s DCE\/RPC protocol implementation\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/01\/VMWare.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/01\/VMWare.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"675\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-01-19T22:17:09+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-10-17T22:48:03+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Active remote code execution vulnerability exploit in VMware - Beacon Lab\" \/>\n\t\t<meta name=\"twitter:description\" content=\"In October 2023 a TrendMicro researcher had discovered and published details of a critical vulnerability in VMware, specifically, in VMware vSphere. This is a management platform for VMware environments, used to manage ESX and ESXi servers and virtual machines. The vulnerability, identified as CVE-2023-34048, arises from an out-of-bounds write weakness in vCenter&#039;s DCE\/RPC protocol implementation\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/01\/VMWare.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/active-remote-code-execution-vulnerability-exploit-in-vmware\\\/#blogposting\",\"name\":\"Active remote code execution vulnerability exploit in VMware - Beacon Lab\",\"headline\":\"Active remote code execution vulnerability exploit in VMware\",\"author\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/gabriela-ratti\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/VMWare.jpg\",\"width\":1200,\"height\":675},\"datePublished\":\"2024-01-19T16:17:09-06:00\",\"dateModified\":\"2024-10-17T17:48:03-06:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/active-remote-code-execution-vulnerability-exploit-in-vmware\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/active-remote-code-execution-vulnerability-exploit-in-vmware\\\/#webpage\"},\"articleSection\":\"Uncategorized\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/active-remote-code-execution-vulnerability-exploit-in-vmware\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/category\\\/uncategorized\\\/#listItem\",\"position\":2,\"name\":\"Uncategorized\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/category\\\/uncategorized\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/active-remote-code-execution-vulnerability-exploit-in-vmware\\\/#listItem\",\"name\":\"Active remote code execution vulnerability exploit in VMware\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/active-remote-code-execution-vulnerability-exploit-in-vmware\\\/#listItem\",\"position\":3,\"name\":\"Active remote code execution vulnerability exploit in VMware\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"telephone\":\"+528007374357\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.mx\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/BeaconLab_V2-03.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/active-remote-code-execution-vulnerability-exploit-in-vmware\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/active-remote-code-execution-vulnerability-exploit-in-vmware\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/BeaconLabMX\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/beaconlabmx\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/gabriela-ratti\\\/#author\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/gabriela-ratti\\\/\",\"name\":\"Gabriela Ratti\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/active-remote-code-execution-vulnerability-exploit-in-vmware\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d08a40ef41baf3a5b15cfd3f9d93069fcd1db17fc70c0a93c3133c7b2eb3a3ab?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Gabriela Ratti\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/active-remote-code-execution-vulnerability-exploit-in-vmware\\\/#webpage\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/active-remote-code-execution-vulnerability-exploit-in-vmware\\\/\",\"name\":\"Active remote code execution vulnerability exploit in VMware - Beacon Lab\",\"description\":\"In October 2023 a TrendMicro researcher had discovered and published details of a critical vulnerability in VMware, specifically, in VMware vSphere. This is a management platform for VMware environments, used to manage ESX and ESXi servers and virtual machines. The vulnerability, identified as CVE-2023-34048, arises from an out-of-bounds write weakness in vCenter's DCE\\\/RPC protocol implementation\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/active-remote-code-execution-vulnerability-exploit-in-vmware\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/gabriela-ratti\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/gabriela-ratti\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/VMWare.jpg\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/active-remote-code-execution-vulnerability-exploit-in-vmware\\\/#mainImage\",\"width\":1200,\"height\":675},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/active-remote-code-execution-vulnerability-exploit-in-vmware\\\/#mainImage\"},\"datePublished\":\"2024-01-19T16:17:09-06:00\",\"dateModified\":\"2024-10-17T17:48:03-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Active remote code execution vulnerability exploit in VMware - Beacon Lab","description":"In October 2023 a TrendMicro researcher had discovered and published details of a critical vulnerability in VMware, specifically, in VMware vSphere. This is a management platform for VMware environments, used to manage ESX and ESXi servers and virtual machines. The vulnerability, identified as CVE-2023-34048, arises from an out-of-bounds write weakness in vCenter's DCE\/RPC protocol implementation","canonical_url":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/#blogposting","name":"Active remote code execution vulnerability exploit in VMware - Beacon Lab","headline":"Active remote code execution vulnerability exploit in VMware","author":{"@id":"https:\/\/beaconlab.us\/en\/author\/gabriela-ratti\/#author"},"publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/01\/VMWare.jpg","width":1200,"height":675},"datePublished":"2024-01-19T16:17:09-06:00","dateModified":"2024-10-17T17:48:03-06:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/#webpage"},"isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/#webpage"},"articleSection":"Uncategorized"},{"@type":"BreadcrumbList","@id":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","position":1,"name":"Home","item":"https:\/\/beaconlab.us\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/#listItem","name":"Uncategorized"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/#listItem","position":2,"name":"Uncategorized","item":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/#listItem","name":"Active remote code execution vulnerability exploit in VMware"},"previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/#listItem","position":3,"name":"Active remote code execution vulnerability exploit in VMware","previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/#listItem","name":"Uncategorized"}}]},{"@type":"Organization","@id":"https:\/\/beaconlab.us\/en\/#organization","name":"Beacon Lab","description":"CSIRT by Cybolt","url":"https:\/\/beaconlab.us\/en\/","telephone":"+528007374357","logo":{"@type":"ImageObject","url":"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png","@id":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/#organizationLogo"},"image":{"@id":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/#organizationLogo"},"sameAs":["https:\/\/twitter.com\/BeaconLabMX","https:\/\/www.linkedin.com\/showcase\/beaconlabmx"]},{"@type":"Person","@id":"https:\/\/beaconlab.us\/en\/author\/gabriela-ratti\/#author","url":"https:\/\/beaconlab.us\/en\/author\/gabriela-ratti\/","name":"Gabriela Ratti","image":{"@type":"ImageObject","@id":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/d08a40ef41baf3a5b15cfd3f9d93069fcd1db17fc70c0a93c3133c7b2eb3a3ab?s=96&d=mm&r=g","width":96,"height":96,"caption":"Gabriela Ratti"}},{"@type":"WebPage","@id":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/#webpage","url":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/","name":"Active remote code execution vulnerability exploit in VMware - Beacon Lab","description":"In October 2023 a TrendMicro researcher had discovered and published details of a critical vulnerability in VMware, specifically, in VMware vSphere. This is a management platform for VMware environments, used to manage ESX and ESXi servers and virtual machines. The vulnerability, identified as CVE-2023-34048, arises from an out-of-bounds write weakness in vCenter's DCE\/RPC protocol implementation","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/#website"},"breadcrumb":{"@id":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/#breadcrumblist"},"author":{"@id":"https:\/\/beaconlab.us\/en\/author\/gabriela-ratti\/#author"},"creator":{"@id":"https:\/\/beaconlab.us\/en\/author\/gabriela-ratti\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/01\/VMWare.jpg","@id":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/#mainImage","width":1200,"height":675},"primaryImageOfPage":{"@id":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/#mainImage"},"datePublished":"2024-01-19T16:17:09-06:00","dateModified":"2024-10-17T17:48:03-06:00"},{"@type":"WebSite","@id":"https:\/\/beaconlab.us\/en\/#website","url":"https:\/\/beaconlab.us\/en\/","name":"Beacon Lab","description":"CSIRT by Cybolt","inLanguage":"en-US","publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"Beacon Lab - CSIRT by Cybolt","og:type":"article","og:title":"Active remote code execution vulnerability exploit in VMware - Beacon Lab","og:description":"In October 2023 a TrendMicro researcher had discovered and published details of a critical vulnerability in VMware, specifically, in VMware vSphere. This is a management platform for VMware environments, used to manage ESX and ESXi servers and virtual machines. The vulnerability, identified as CVE-2023-34048, arises from an out-of-bounds write weakness in vCenter's DCE\/RPC protocol implementation","og:url":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/","og:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/01\/VMWare.jpg","og:image:secure_url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/01\/VMWare.jpg","og:image:width":1200,"og:image:height":675,"article:published_time":"2024-01-19T22:17:09+00:00","article:modified_time":"2024-10-17T22:48:03+00:00","twitter:card":"summary_large_image","twitter:site":"@BeaconLabMX","twitter:title":"Active remote code execution vulnerability exploit in VMware - Beacon Lab","twitter:description":"In October 2023 a TrendMicro researcher had discovered and published details of a critical vulnerability in VMware, specifically, in VMware vSphere. This is a management platform for VMware environments, used to manage ESX and ESXi servers and virtual machines. The vulnerability, identified as CVE-2023-34048, arises from an out-of-bounds write weakness in vCenter's DCE\/RPC protocol implementation","twitter:creator":"@BeaconLabMX","twitter:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2024\/01\/VMWare.jpg"},"aioseo_meta_data":{"post_id":"6458","title":null,"description":null,"keywords":[],"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":[],"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2024-10-11 18:30:04","updated":"2025-09-24 05:43:25","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/category\/uncategorized\/\" title=\"Uncategorized\">Uncategorized<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tActive remote code execution vulnerability exploit in VMware\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/beaconlab.us\/en\/"},{"label":"Uncategorized","link":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/"},{"label":"Active remote code execution vulnerability exploit in VMware","link":"https:\/\/beaconlab.us\/en\/active-remote-code-execution-vulnerability-exploit-in-vmware\/"}],"_links":{"self":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/posts\/6458","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/comments?post=6458"}],"version-history":[{"count":1,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/posts\/6458\/revisions"}],"predecessor-version":[{"id":6831,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/posts\/6458\/revisions\/6831"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media\/6297"}],"wp:attachment":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media?parent=6458"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/categories?post=6458"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/tags?post=6458"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}