CVE-2020-3992criticalunder attackransomwareCWE-416

CVE-2020-3992: critical vulnerability in VMware ESXi

Published · Updated

100Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 9.8epss 83%
from disclosure to weapon42 days
Published on NVDOct 20
1st PoC+42d
CISA KEV+379d
exploitation probability
83%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
5 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

OpenSLP service in VMware ESXi has a memory error that allows attackers on the management network to execute code remotely by sending crafted requests to port 427. This is a critical vulnerability because it gives attackers complete control over the virtualization platform.

Technical detail

A use-after-free vulnerability in OpenSLP allows remote code execution when an attacker with access to port 427 on the management network sends specially crafted packets. The vulnerability requires network access to the ESXi host but no authentication, resulting in arbitrary code execution with hypervisor privileges.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · VMware ESXi
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.