Check Point Advisories

VMware vCenter Server Memory Corruption (CVE-2023-20894)

Check Point Reference: CPAI-2023-0704
Date Published: 12 Aug 2024
Severity: Critical
Last Updated: Monday 12 August, 2024
Source:
Industry Reference:CVE-2023-20894
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? VMware vCenter Server prior to 7.0
VMWare vCenter Server 7.0
VMWare vCenter Server 7.0a
VMWare vCenter Server 7.0b
VMWare vCenter Server 7.0c
VMWare vCenter Server 7.0d
VMware vCenter Server 7.0 Update 1
VMware vCenter Server 7.0 Update 1a
VMware vCenter Server 7.0 Update 1c
VMware vCenter Server 7.0 Update 1d
VMware vCenter Server 7.0 Update 2
VMware vCenter Server 7.0 Update 2a
VMware vCenter Server 7.0 Update 2b
VMware vCenter Server 7.0 Update2c
VMware vCenter Server 7.0 Update2d
VMware vCenter Server 7.0 Update 3
VMware vCenter Server 7.0 Update3a
VMware vCenter Server 7.0 Update3c
VMware vCenter Server 7.0 Update3d
VMware vCenter Server 7.0 Update3e
VMware vCenter Server 7.0 Update3f
VMware vCenter Server 7.0 Update3g
VMware vCenter Server 7.0 Update3h
VMware vCenter Server 7.0 Update3i
VMware vCenter Server 7.0 Update 3j
VMware vCenter Server 7.0 Update 3k
VMware vCenter Server 7.0 Update 3l
VMware vCenter Server 8.0
VMware vCenter Server 8.0 A
VMware vCenter Server 8.0 B
VMware vCenter Server 8.0 C
VMware vCenter Server 8.0 Update 1
VMware vCenter Server 8.0 Update 1a
Vulnerability Description A memory corruption vulnerability exists in VMware vCenter Server. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the affected system.

Protection Overview

This protection detects attempts to exploit this vulnerability.

In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.

Security Gateway R81 / R80 / R77 / R75

  1. In the IPS tab, click Protections and find the VMware vCenter Server Memory Corruption (CVE-2023-20894) protection using the Search tool and Edit the protection's settings.
  2. Install policy on all Security Gateways.

This protection's log will contain the following information:

Attack Name:  Application Servers Protection Violation.
Attack Information:  VMware vCenter Server Memory Corruption (CVE-2023-20894)

×
  Feedback
This website uses cookies for its functionality and for analytics and marketing purposes. By continuing to use this website, you agree to the use of cookies. For more information, please read our Cookies Notice.
OK