VMware administrators were urged to rapidly patch vCenter Server, Cloud Foundation, and Aria Automation after disclosure and active exploitation of critical vulnerabilities including CVE-2023-34048 and CVE-2023-34063. CVE-2023-34048 is a critical unauthenticated remote code execution flaw in vCenter's DCE/RPC implementation, while CVE-2023-34063 is a critical missing access control issue that can let an authenticated attacker access remote organizations and workflows; CVE-2023-34056 was also cited as a lower-severity vCenter issue. CSIRT.SK reported that more than 2,000 vCenter servers were exposed and noted CISA had highlighted active exploitation of CVE-2023-34063, with defenders advised to patch immediately, upgrade Aria Automation to 8.16, and closely monitor TCP ports 2012, 2014, and 2020 because no mitigation exists for CVE-2023-34048 beyond updating.
VMware's Cloud Foundation guidance tied remediation to a detailed compatibility matrix for applying vCenter patches with the Async Patch Tool (AP Tool) across supported VCF releases and SKUs, including VCF on VxRail. The matrix lists supported vCenter 7.0 U3 and 8.0 U1/U2/U3 patch bundles, flags cases with no upgrade path for some major VCF lines, and notes that certain VCF 5.2/5.2.1 upgrades must be performed through Flexible BOM instead of AP Tool. VMware also specifically recommended moving VCF 5.2.1 environments to vCenter 8.0 U3d rather than the bundled 8.0 U3c to address vulnerabilities disclosed in VMSA-2024-0019.2, while warning that some vCenter 7.0 U3 patching operations also update multiple SDDC Manager services.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
VMware's Async Patch Tool compatibility guidance specifically recommends upgrading VCF 5.2.1 environments to vCenter 8.0 U3d instead of the 8.0 U3c version packaged with VCF 5.2.1 to address CVEs disclosed in VMSA-2024-0019.2. The same guidance also notes patching constraints and cases where upgrades must use Flexible BOM rather than the Async Patch Tool.
VMware published updated mitigation and patch guidance for CVE-2023-34063 under VMSA-2024-0001, recommending Aria Automation 8.16 and providing version-specific patches for supported earlier releases. The company said the original patches mitigated the flaw but introduced a custom forms issue documented in KB 314888, so the reissued patches both address the vulnerability and fix that regression.
On 2024-02-05, CSIRT.SK published an alert about actively exploited critical VMware vulnerabilities, emphasizing CVE-2023-34063 and CVE-2023-34048 and noting that more than 2,000 VMware vCenter servers were reportedly exposed. It urged immediate patching, upgrading Aria Automation to version 8.16, and monitoring TCP ports 2012, 2014, and 2020 because no mitigation existed for CVE-2023-34048.
CSIRT.SK reported that CISA had highlighted active exploitation of VMware flaw CVE-2023-34063, a critical missing access control vulnerability affecting Aria Automation, Cloud Foundation, and vCenter Server. The notice also described CVE-2023-34048 as a critical unauthenticated vCenter Server RCE and CVE-2023-34056 as a lower-severity related flaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
kb.vmware.com
Open sourcecsirt.sk
Open sourcekb.vmware.com
Open sourcevmware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.