LOWCVSS 9.8 · CRITICALCISA KEV
Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
- Prioritize remediation for vmware vcenter_server systems immediately
- Assume compromise if assets are exposed
- Track advisory updates for patch or workaround availability
Recommended action window: Immediate (within 24h)
NVD description
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.