CVE-2020-3992

KEV
🔴 Łataj teraz

Błąd use-after-free w OpenSLP w VMware ESXi umożliwia zdalne wykonanie kodu.

CVSS
9.8
EPSS
83.0%
Exploit
weaponized
Vendor
vmware
Opis źródłowy (NVD)

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.

rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Tak
FIRST EPSS (prawdopodobieństwo exploita)83.0%
Opublikowano (NVD)2020-10-20 17:15:12 UTC
Ostatnia modyfikacja (NVD)2026-08-12 05:17:31 UTC
Referencje