Use-after-free in VMware ESXi - CVE-2020-3992

 

Use-after-free in VMware ESXi - CVE-2020-3992

Published: October 20, 2020 / Updated: April 19, 2023


Vulnerability identifier: #VU47750
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3992
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the OpenSLP service. A remote attacker can can send specially crafted SLP message to port 427/udp, trigger a use-after-free error and execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

VMware ESXi
Dell EMC VxRail Appliance

How to mitigate CVE-2020-3992

Install updates from vendor's website.

VMware ESXi - addressed in versions ESXi_7.0.1-0.0.16850804, ESXi650-202007101-SG, ESXi670-202008101-SG
Dell EMC VxRail Appliance - addressed in versions 4.5.452, 4.7.525, 7.0.101

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins