ZeroHour

CVE-2020-3992

KEV ransomwarelarge

Use-After-Free RCE in VMware ESXi OpenSLP Service (Port 427)

CISA: VMware ESXi OpenSLP Use-After-Free Vulnerability

CVSS 3.1
9.8 critical
EPSS
83%p100
Published
()
KEV added
AI analysis

CVE-2020-3992 is a use-after-free (CWE-416) in the OpenSLP service used by VMware ESXi, rated critical at CVSS 9.8. An unauthenticated attacker with access to port 427 on an ESXi host's management network can send crafted SLP traffic that triggers the memory-reuse flaw and gains remote code execution on the hypervisor. Successful exploitation grants full control of the ESXi host, and attackers have used these OpenSLP flaws in the ESXiArgs ransomware campaign to encrypt the disks of hosted virtual machines. Affected products are ESXi 7.0, 6.7 and 6.5 prior to the October 2020 patch releases (as well as the related VMware Cloud Foundation). The flaw is in CISA's KEV catalog (added 2021-11-03) with ransomware use confirmed, and EPSS assigns an 83% probability of exploitation within 30 days (100th percentile); no public PoC is listed in the source data.

What to do: Apply VMware's ESXi security patches: ESXi_7.0.1-0.0.16850804 (7.0), ESXi670-202010401-SG (6.7), or ESXi650-202010401-SG (6.5), or the corresponding VMware Cloud Foundation update, per CISA's required action. As interim mitigation, restrict or disable the SLP service and firewall port 427 so ESXi management interfaces are not reachable from the internet. Because ransomware use is confirmed, check hosts for signs of compromise; CISA has published an ESXiArgs recovery script for affected deployments.

Affected
vmware ESXi7.0 before ESXi_7.0.1-0.0.16850804
vmware ESXi6.7 before ESXi670-202010401-SG
vmware ESXi6.5 before ESXi650-202010401-SG
vmware Cloud Foundation
Estimated exposure
large≈90,000-100,000 internet-exposed ESXi hosts on port 427 (many more reachable only on internal management networks) — Public internet scans during the ESXiArgs ransomware wave counted on the order of 100,000 ESXi servers exposing SLP on port 427, out of an overall installed base in the millions of hosts, so the directly exposed population is estimated at…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.

CISA Known Exploited Vulnerability
Affected
VMware ESXi
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
vmware
Products
cloud foundation, esxi
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news