LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-3992: VMware ESXi OpenSLP Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-3992 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.

CVE-2020-3992 is a use-after-free vulnerability in the OpenSLP service on VMware ESXi. An attacker who already has access to the management network and can reach port 427 may achieve remote code execution on the hypervisor. Because ESXi underpins virtualized workloads, successful exploitation can give an adversary control over guest systems and storage. Public reporting links this issue to ransomware activity, so timely response matters for any environment still running the affected component.

How it works

The weakness is classified as CWE-416 (use-after-free). In this class of flaw, a program continues to use a region of memory after it has been freed. An attacker who can influence the allocation and freeing pattern may corrupt program state and redirect execution. On VMware ESXi the vulnerable code resides in OpenSLP. According to the CISA summary, an attacker positioned on the management network with reachability to TCP/UDP port 427 can trigger the condition and obtain remote code execution. Exact packet sequences or heap-grooming details are not required for defenders; the practical takeaway is that unauthenticated or lightly authenticated traffic to the SLP service is sufficient once network access exists. Confirm any deeper technical description against the vendor advisory.

Am I affected? How to find it in your systems

VMware ESXi is commonly deployed as bare-metal hypervisors in data centers, remote offices, and lab environments. Inventory every ESXi host—standalone, clustered under vCenter, or nested. Check whether the OpenSLP service is present and listening on port 427. Because precise affected version ranges are not restated here, compare each host’s build number directly with the fixed releases listed in VMware’s advisory for CVE-2020-3992.

How to remediate

The primary action is to apply the updates VMware released for this CVE, following the vendor’s instructions exactly. CISA likewise directs organizations to apply updates per vendor guidance. After patching, verify the new build number and confirm that the OpenSLP service either no longer exposes the vulnerable code path or has been updated.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls focused on the attack path.

If your data may have been exposed

Vulnerabilities that enable remote code execution on hypervisors and that have been used by ransomware operators frequently precede data theft or encryption. If you have reason to believe an ESXi host was compromised, treat connected datastores and guest workloads as potentially exposed. Rotate credentials, review backup integrity, and examine guest systems for follow-on activity. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVMware · ESXi
WeaknessCWE-416
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities