VMware finally fixed critical CVE-2020
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-3992 | Use-After-Free RCE in VMware ESXi OpenSLP Service (Port 427) CVE-2020-3992 is a use-after-free (CWE-416) in the OpenSLP service used by VMware ESXi, rated critical at CVSS 9.8. An unauthenticated attacker with access to port 427 on an ESXi host's management network can send crafted SLP traffic that triggers the memory-reuse flaw and gains remote code execution on the hypervisor. Successful exploitation grants full control of the ESXi host, and attackers have used these OpenSLP flaws in the ESXiArgs ransomware campaign to encrypt the disks of hosted virtual machines. Affected products are ESXi 7.0, 6.7 and 6.5 prior to the October 2020 patch releases (as well as the related VMware Cloud Foundation). The flaw is in CISA's KEV catalog (added 2021-11-03) with ransomware use confirmed, and EPSS assigns an 83% probability of exploitation within 30 days (100th percentile); no public PoC is listed in the source data. Do: Apply VMware's ESXi security patches: ESXi_7.0.1-0.0.16850804 (7.0), ESXi670-202010401-SG (6.7), or ESXi650-202010401-SG (6.5), or the corresponding VMware Cloud Foundation update, per CISA's required action. As interim mitigation, restrict or disable the SLP service and firewall port 427 so ESXi management interfaces are not reachable from the internet. Because ransomware use is confirmed, check hosts for signs of compromise; CISA has published an ESXiArgs recovery script for affected deployments. | 9.8 | 83% | KEV ransomware |
| large≈90,000-100,000 internet-exposed ESXi hosts on port 427 (many more reachable only on internal management networks) |
Full article326 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
November 05, 2020
![]()
VMware has released new patches for ESXi after learning that a fix released in October for the critical CVE-2020-3992 flaw was incomplete.
The virtualization giant VMware has released new fixes for ESXi after learning that a patch released in October for the critical CVE-2020-3992 flaw was incomplete.
The CVE-2020-3992 vulnerability is a use-after-free bug issue that affects the OpenSLP service in ESXi, it could be exploited by a remote, unauthenticated attacker to execute arbitrary code in the context of the SLP daemon.
The flaw exists is caused by the lack of validating the existence of an object prior to performing operations on it.
VMware pointed out that in order to exploit the flaw, the attacker needs to be on the management network and have access to port 427 on an ESXi machine.
“OpenSLP as used in ESXi has a use-after-free issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.” reads the advisory published by the company. “A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.”
The vulnerability was reported to vendor on July 22, 2020 by Lucas Leong of Trend Micro’s Zero Day Initiative (ZDI).
VMware learned about the security hole in July from Lucas Leong of Trend Micro’s Zero Day Initiative (ZDI). On October 20, 2020, an advisory was publicly released.
The company initially failed to fix the vulnerability, it updated its initial advisory this week informing its customers that the patches had been incomplete.
Now the company has released security patches to address the flaw in ESXi 6.5, 6.7 and 7.0. The vulnerability has yet to be fixed in VMware Cloud Foundation.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, ESXi)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/110433/security/vmware-cve-2020-3992-esxi.html