Junglewise Threat Intelligence

CVE-2020-3992: VMware ESXi OpenSLP Use-After-Free Vulnerability

CVE-2020-3992 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: VMware ESXi. Vendors: VMware.

Executive brief

OpenSLP as used in VMware ESXi contains a use-after-free vulnerability in the OpenSLP service. A remote attacker with access to port 427 on the management network can exploit this to execute arbitrary code on the host.

Affected products

  • VMware ESXi 7.0 before ESXi_7.0.1-0.0.16850804
  • VMware ESXi 6.7 before ESXi670-202010401-SG
  • VMware ESXi 6.5 before ESXi650-202010401-SG

Timeline

  • 2020-10-20: patched: Vendor released patches for ESXi 6.5, 6.7, and 7.0.
  • 2021-11-03: disclosed: NVD publication date.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: exploited: Confirmed as exploited in the wild per CISA KEV catalog.

Related threats