Record summary

CVE-2020-3992 has a selected CVSS score of 9.8 (critical); EIP currently links 2 repository PoCs. CISA lists CVE-2020-3992 in KEV and reports its use in known ransomware campaigns.

Description

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 3, 2021 · CISA
VulnCheck KEV
Listed · Nov 11, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · CISA

Available material

Repository PoCs
2

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 19, 2021 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CISAVersion data not supplied

VMware ESXi

CVE ListVMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG)affected

Proofs of concept

2

Repository PoCs

GitHubHynekPetrak/CVE-2019-5544_CVE-2020-3992Repository PoCby HynekPetrakStars: 49Not analyzed4 files

23.2 KiB · linked to 3 vulnerabilities

GitHub

PoC details
GitHubdgh05t/VMware_ESXI_OpenSLP_PoCsRepository PoCby dgh05tStars: 67Not analyzed3 files

3.4 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

5