Skip to content
COOEY

EXPOSURES › CVE-2020-3992

CVE-2020-3992

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-3992 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

VMware ESXi's OpenSLP service had a remotely exploitable use-after-free vulnerability linked to ransomware activity, requiring immediate patching and network segmentation review.

CVE-2020-3992 in VMware ESXi allowed remote code execution via port 427, and was actively exploited, including by ransomware. DIB organizations using ESXi must immediately patch and segment management networks to prevent compromise; failure to do so violates NIST 800-171 controls related to access control and vulnerability management.

Shame score — A critical, remotely exploitable vulnerability with ransomware links demonstrates a significant failure in VMware's secure development lifecycle and risk management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
VMware's OpenSLP vulnerability (CVE-2020-3992) is a severe use-after-free flaw allowing remote code execution on the management network, but the provided sources lack direct commentary on VMware's res
tech-insider.org ↗ severe-fallout -0.90
Tech Insider highlights a different VMware flaw (CVE-2026-59310) with severe fallout, but this is unrelated to CVE-2020-3992 and thus irrelevant to the specific event.
"A single flaw in VMware vCenter has turned into one of the more consequential enterprise-security stories of August 2026."
The Hacker News ↗ severe-fallout -0.90
The Hacker News discusses a different vendor (Oracle) and flaw, making it entirely irrelevant to the VMware CVE-2020-3992 event.
"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog."
cooey ↗ severe-fallout -0.80
NVD entry confirms the severe technical nature of the flaw but offers no vendor response or handling assessment.
"VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution."
xposedornot.com ↗ severe-fallout +0.00
XposedOrNot provides a breach directory but contains no commentary on VMware's handling of CVE-2020-3992.
www.upguard.com ↗ severe-fallout +0.00
UpGuard provides vendor risk reporting services but contains no commentary on VMware's handling of CVE-2020-3992.
github.com ↗ severe-fallout +0.00
GitHub mirrors CISA KEV data but contains no commentary on VMware's handling of CVE-2020-3992.
www.cvefind.com ↗ severe-fallout +0.00
CVE Find provides vulnerability intelligence but contains no commentary on VMware's handling of CVE-2020-3992.
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized