Sploitus

CVE-2020-3992

5 known exploits for CVE-2020-3992

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.

Affected products
Vmware Esxi
Vmware Cloud Foundation
< 3.10.1.2, 4.1.0.1
Vmware Esxi
= 6.5, 6.7, 7.0.0
Fix
Available
CVSS 2.0
10.0 HIGH
CVSS 3.1
9.8 CRITICAL
EPSS
83.0% (100th percentile)
Weakness
CWE-416
NVD status
Analyzed
Published
2020-10-20
CVE-2020-3992 at NVD
Authoritative description, scoring and affected products

5 known exploits for CVE-2020-3992

Proof-of-concept code and exploit modules indexed by Sploitus