CISA Known Exploited Vulnerability

CVE-2020-3992 Ransomware

VMware · ESXi

VMware ESXi OpenSLP Use-After-Free Vulnerability

Date added
BOD 22-01 due date
CWE CWE-416
Ransomware Known

CISA description

VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.

Required action

Apply updates per vendor instructions.