VMware plugs critical flaw in vCenter Server, patch ASAP!
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-3952 | Authentication Bypass in VMware vCenter Server 6.7 vmdir (CVE-2020-3952) CVE-2020-3952 is a critical missing-authentication flaw (CWE-306, CVSS 9.8) in vmdir, the VMware Directory Service that ships with vCenter Server as part of an embedded or external Platform Services Controller (PSC). Under certain conditions, vmdir does not correctly implement access controls, so an unauthenticated attacker with network access to the directory service (LDAP) can retrieve directory data without valid credentials. Because that directory data includes vCenter Single Sign-On account information such as credential material, public proof-of-concept content treats the bug as an authentication bypass that can lead to full privileged access to vCenter. Any organization running VMware vCenter Server 6.7 with an embedded or external PSC is affected. Exploitation is confirmed: the flaw was added to CISA's KEV on 2021-11-03, and EPSS assigns a 90.4% probability of exploitation within 30 days (ransomware linkage: unknown). Do: Upgrade vCenter Server 6.7 to the patched release from VMware (the fix shipped in the 6.7 U3l update per VMware advisory VMSA-2020-0004; apply updates per vendor instructions as required by the KEV listing). Until patched, restrict untrusted network access to vmdir's LDAP service (TCP 389/636) on embedded/external PSCs and review directory logs for unauthenticated access. Inventory whether each vCenter deployment uses an embedded or external PSC, since both topologies are affected. | 9.8 | 90% | KEV PoC |
| largetens of thousands of internet-exposed vCenter Servers (~60,000+ observed in public scans at the time), with hundreds of thousands of deployments worldwide… |
Full article346 words · extracted from helpnetsecurity.com · click to collapse
VMware has fixed a critical vulnerability (CVE-2020-3952) affecting vCenter Server, which can be exploited to extract highly sensitive information that could be used to compromise vCenter Server or other services which depend on the VMware Directory Service (vmdir) for authentication.

About CVE-2020-3952
VMware vSphere is VMware’s cloud computing virtualization platform. vCenter Server is server management software for controlling VMware vSphere environments.
“Under certain conditions vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 10.0,” the company noted in an advisory published last week.
The vulnerability exists in vCenter Server 6.7, running on Windows or a virtual appliance, only if the installations were upgraded from a previous release line such as 6.0 or 6.5. It can be exploited by a malicious actor with network access to an affected vmdir deployment.
“Clean installations of vCenter Server 6.7 (embedded or external PSC) are not affected. vCenter Server versions 6.5. and 7.0 are unaffected,” the company pointed out.
How to fix the problem?
Administrators are advised to check whether their deployments are affected (here is how) and, if they are, update them to version 6.7u3f or 7.0.
There are no effective workarounds for this problem, though there are compensating controls admins can implement to minimize/mitigate the risk associated with it.
Bob Plankers, who works in the Cloud Platforms group at VMware, provided additional insight on those controls, on why it’s better to patch, and answered a number of questions admins may have regarding this flaw and the implementation of the fix.
CVE-2020-3952 was privately reported to VMware and there are currently no public PoC exploits for it. The company did not mention whether the flaw is being exploited in the wild, so it’s likely that it isn’t (yet).
UPDATE (April 17, 2020, 12:55 a.m. PT):
Guardicore researchers revealed how they discovered the vulnerability and released Proof of Concept code on GitHub.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2020/04/14/cve-2020-3952/