vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.
https://cloud.google.com/blog/topics/threat-intelligence/uncovering-unc3886-espionage-operations
https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf
https://meterpreter.org/cve-2023-34048-inside-the-zero-day-vulnerability-exploited-by-unc3886/
https://www.theregister.com/2023/10/25/vmware_vcenter_critical_flaw/
https://www.vmware.com/security/advisories/VMSA-2023-0023.html