{"id":"CVE-2020-3992","title":"OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue","summary":"OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416","CWE-416"],"vendor":"vmware","product":"cloud_foundation","affected":["cloud_foundation >= 3.0, < 3.10.1.2","cloud_foundation >= 4.0, < 4.1.0.1","esxi = 6.5","esxi = 6.7","esxi = 7.0.0"],"patched":["cloud_foundation 4.1.0.1"],"published":"2020-10-20","updated":"2026-08-12","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-3992","references":[{"url":"https://www.vmware.com/security/advisories/VMSA-2020-0023.html","label":"security@vmware.com"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-1377/","label":"security@vmware.com"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-1385/","label":"security@vmware.com"},{"url":"https://www.vmware.com/security/advisories/VMSA-2020-0023.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-1377/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-20-1385/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3992","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.83015,"epssPercentile":0.99658,"kev":true,"kevDateAdded":"2021-11-03","kevDueDate":"2022-05-03","kevRansomware":true,"exploited":true,"zeroDay":true,"ingestedAt":"2026-08-12T05:52:07.652Z","exploits":{"github":2,"githubRepos":["https://github.com/HynekPetrak/CVE-2019-5544_CVE-2020-3992","https://github.com/dgh05t/VMware_ESXI_OpenSLP_PoCs"],"checkedAt":"2026-09-23T07:13:17.113Z"},"exploitAvailable":true,"slug":"CVE-2020-3992","body":"## Overview\n\nOpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.\n\n## Affected\n\n- `cloud_foundation >= 3.0, < 3.10.1.2`\n- `cloud_foundation >= 4.0, < 4.1.0.1`\n- `esxi = 6.5`\n- `esxi = 6.7`\n- `esxi = 7.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `cloud_foundation 4.1.0.1`","depth":"hadal","depthScore":100,"depthScoreParts":{"impact":53.9,"likelihood":16.6,"exploitation":25,"ransomware":5},"changes":[{"seq":4483,"id":"CVE-2020-3992","ts":1788887183423,"field":"exploit_available","old":"false","new":"true"},{"seq":3366,"id":"CVE-2020-3992","ts":1788886302290,"field":"exploit_available","old":"true","new":"false"},{"seq":2221,"id":"CVE-2020-3992","ts":1788882971977,"field":"exploit_available","old":"false","new":"true"},{"seq":1250,"id":"CVE-2020-3992","ts":1788882383544,"field":"exploit_available","old":"true","new":"false"},{"seq":364,"id":"CVE-2020-3992","ts":1788881818917,"field":"exploit_available","old":"false","new":"true"}]}