Description
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
Remediation
Upgrade to the latest version of VMware vCenter.
References
Related Vulnerabilities
ColdFusion CFC Deserialization RCE (CVE-2023-26359/CVE-2023-26360)
Drupal Core 8.6.x Remote Code Execution (8.6.0 - 8.6.9)
Ivanti Sentry Authentication Bypass (CVE-2023-38035)
WordPress Plugin Plainview Activity Monitor Remote Command Execution (20161228)
WordPress Plugin WordPress Landing Pages Remote Code Execution (1.9.0)