CVE-2020-3952
published 2020-04-10CVE-2020-3952: Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not…
PriorityP194critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
90.38%
99.8th percentile
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
\x30\x05\x02\x01\x04\x42\x00
sigma↗
matchers: words: ['RetrieveServiceContentResponse', 'urn:vim'] in HTTP response body with Content-Type: text/xml and status 200
- →Detect unauthenticated (anonymous-bind) LDAP connections to port 389 on vCenter Server, especially those attempting to add or modify users in cn=Users,dc=vsphere,dc=local or modify membership of cn=Administrators,cn=Builtin,dc=vsphere,dc=local. ↗
- →Monitor for LDAP Add (opcode 0x68) and Modify (opcode 0x66) requests to vmdir on port 389 without prior successful authentication, particularly targeting vsphere.local directory objects. ↗
- →Alert on LDAP bind responses returning result code 0x31 (invalidCredentials) followed immediately by LDAP Add or Modify operations — the exploit proceeds even after a failed bind. ↗
- →Detect HTTP POST requests to /sdk/ with SOAPAction 'urn:vim25/6.5' and response body containing 'RetrieveServiceContentResponse' as a reconnaissance indicator against vCenter. ↗
- →Vulnerability only affects vCenter Server 6.7 instances that were upgraded from a previous release (6.0 or 6.5); clean 6.7 installs are not affected. Scope detection efforts accordingly. ↗
- →Monitor for new user creation in vsphere.local LDAP directory (objectClass: user under cn=Users,dc=vsphere,dc=local) with attribute vmwPasswordNeverExpires set to True, which is a characteristic of exploit-created accounts. ↗
- ·The exploit requires network access to port 389 (LDAP) on the vCenter Server or PSC. Restricting network access to vmdir/LDAP from untrusted networks reduces exposure. ↗
- ·The Metasploit module also supports authenticated operation via BIND_DN and LDAPPassword options, meaning the same module can be used for both exploitation and legitimate admin tasks — authenticated use should not be treated as benign without context. ↗
- ·The exploit default timeout is 5 seconds; scanners or IDS with very short connection timeouts may miss slow exploit attempts. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
VMware vCenter Server Information Disclosure Vulnerability
cisa·2021-11-03·CVSS 9.8
CVE-2020-3952 [CRITICAL] CWE-306 VMware vCenter Server Information Disclosure Vulnerability
Vulnerability: VMware vCenter Server Information Disclosure Vulnerability
Affected: VMware vCenter Server
VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-3952
Remediation Due Date: 2022-05-03
VMware
VMware vCenter Server updates address sensitive information disclosure vulnerability in the VMware Directory Service (vmdir) (CVE-2020-3952)
vendor_vmware·2020-04-09·CVSS 9.8
CVE-2020-3952 [CRITICAL] VMware vCenter Server updates address sensitive information disclosure vulnerability in the VMware Directory Service (vmdir) (CVE-2020-3952)
VMSA-2020-0006: VMware vCenter Server updates address sensitive information disclosure vulnerability in the VMware Directory Service (vmdir) (CVE-2020-3952)
Under certain conditions[1] vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 10.0.
CVEs: CVE-2020-3952
Affected products: VMware vCenter Server
GHSA
GHSA-rqpw-v3g2-qccx: Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not
ghsa_unreviewed·2022-05-24
CVE-2020-3952 [MEDIUM] CWE-287 GHSA-rqpw-v3g2-qccx: Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
VulnCheck
VMware vCenter Server Information Disclosure Vulnerability
vulncheck·2020·CVSS 9.8
CVE-2020-3952 [CRITICAL] CWE-306 VMware vCenter Server Information Disclosure Vulnerability
VMware vCenter Server Information Disclosure Vulnerability
VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information.
Affected: VMware vCenter Server
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://blog.qualys.com/vulnerabilities-threat-research/2025/05/08/inside-lockbit-defense-lessons-from-the-leaked-lockbit-negotiations
Exploit PoC: https://vulncheck.com/xdb/2dc27965feae; https://vulncheck.com/xdb/12b54f8ddd08;
No detection rules found.
Exploit-DB
VMware vCenter Server 6.7 - Authentication Bypass
exploitdb·2020-06-01·CVSS 6.5
CVE-2020-3952 [MEDIUM] VMware vCenter Server 6.7 - Authentication Bypass
VMware vCenter Server 6.7 - Authentication Bypass
---
# Exploit Title: VMware vCenter Server 6.7 - Authentication Bypass
# Date: 2020-06-01
# Exploit Author: Photubias
# Vendor Advisory: [1] https://www.vmware.com/security/advisories/VMSA-2020-0006.html
# Version: vCenter Server 6.7 before update 3f
# Tested on: vCenter Server Appliance 6.7 RTM (updated from v6.0)
# CVE: CVE-2020-3952
#!/usr/bin/env python3
'''
Copyright 2020 Photubias(c)
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the impli
Metasploit
VMware vCenter Server vmdir Authentication Bypass
metasploit
VMware vCenter Server vmdir Authentication Bypass
VMware vCenter Server vmdir Authentication Bypass
This module bypasses LDAP authentication in VMware vCenter Server's vmdir service to add an arbitrary administrator user. Version 6.7 prior to the 6.7U3f update is vulnerable, only if upgraded from a previous release line, such as 6.0 or 6.5. Note that it is also possible to provide a bind username and password to authenticate if the target is not vulnerable. It will add an arbitrary administrator user the same way.
Nuclei
VMware vCenter Server LDAP Broken Access Control
nuclei·CVSS 9.8
CVE-2020-3952 [CRITICAL] VMware vCenter Server LDAP Broken Access Control
VMware vCenter Server LDAP Broken Access Control
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
Template:
id: CVE-2020-3952
info:
name: VMware vCenter Server LDAP Broken Access Control
author: 0x_Akoko
severity: critical
description: |
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
impact: |
Unauthorized users may access sensitive functions, potentially leading to privilege escalation or data exposure.
remediation: |
Apply the latest security patches and updates provided by VMware to address access control is
Metasploit
VMware vCenter Server vmdir Information Disclosure
metasploit
VMware vCenter Server vmdir Information Disclosure
VMware vCenter Server vmdir Information Disclosure
This module uses an anonymous-bind LDAP connection to dump data from the vmdir service in VMware vCenter Server version 6.7 prior to the 6.7U3f update, only if upgraded from a previous release line, such as 6.0 or 6.5. If the bind username and password are provided (BIND_DN and LDAPPassword options), these credentials will be used instead of attempting an anonymous bind.
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
#### Table of Contents
- Who is LockBit? How it Evolved and Operates
- Monero: The Coin of the Realm
- Patch or Mitigate Now: Critical CVEs Exploited by LockBit
- Beyond Traditional Endpoints: Other Compromised Systems
- Initial Access and Deployment
- Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
## Table of Contents
Who is LockBit? How it Evolved and Operates
Monero: The Coin of the Realm
Patch or Mitigate Now: Critical CVEs Exploited by LockBit
Beyond Traditional Endpoints: Other Compromised Systems
Initial Access and Deployment
Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will leverage
Tenable
CVE-2022-22948: VMware vCenter Server Sensitive Information Disclosure Vulnerability
blogs_tenable·2022-03-30·CVSS 6.5
[MEDIUM] CVE-2022-22948: VMware vCenter Server Sensitive Information Disclosure Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
13th April – Threat Intelligence Bulletin
blogs_checkpoint·2020-04-13
CVE-2020-3952 13th April – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 13th April – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 13th April 2020, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Hammersmith Medicines Research LTD (HMR), a research firm on standby to perform live trials of coronavirus vaccines, has suffered a data breach by the Maze ransomware . HMR has decided not to pay the ransom, only to have stolen data published a week later on the attackers “News” site. The attack compromised volunteers’
Tenable
CVE-2020-3952: Sensitive Information Disclosure in VMware vCenter Server (VMSA-2020-0006)
blogs_tenable·2020-04-10·CVSS 9.8
[CRITICAL] CVE-2020-3952: Sensitive Information Disclosure in VMware vCenter Server (VMSA-2020-0006)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://packetstormsecurity.com/files/157896/VMware-vCenter-Server-6.7-Authentication-Bypass.htmlhttps://www.vmware.com/security/advisories/VMSA-2020-0006http://packetstormsecurity.com/files/157896/VMware-vCenter-Server-6.7-Authentication-Bypass.htmlhttps://www.vmware.com/security/advisories/VMSA-2020-0006https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3952
2020-04-10
Published
2021-11-03
Added to CISA KEV
Exploited in the wild