November 3, 2021 · Applied Cybernetics Group
CVE-2020-3992 — VMware ESXi
known ransomware use
VMware ESXi OpenSLP Use-After-Free Vulnerability
- Added to KEV
2021-11-03- Federal due date
2022-05-03- Vendor
- VMware
- Product
- ESXi
- EPSS
- 99.7th percentile (score 0.830, as of
2026-09-16) - NVD CVSS v3.1
- 9.8 (CRITICAL)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2020-3992
CISA short description
VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.
Required action
Apply updates per vendor instructions.
NVD description
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.