CVE-2020-3992
published 2020-10-20CVE-2020-3992: OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free…
PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
83.02%
99.6th percentile
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2010_service_pack_2 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_word_2010_service_pack_2 | — | — |
| msrc | microsoft_word_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_word_2013_service_pack_1 | — | — |
| msrc | microsoft_word_2016 | — | — |
| vmware | cloud_foundation | >= 3.0 < 3.10.1.2 | 3.10.1.2 |
| vmware | cloud_foundation | >= 4.0 < 4.1.0.1 | 4.1.0.1 |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for inbound TCP connections to port 427 (OpenSLP) on ESXi hosts, especially from hosts outside the management network, as this is the attack entry point for CVE-2020-3992 exploitation. ↗
- →Check ESXi hosts in /tmp for the presence of files named 'encrypt', 'encrypt.sh', and 'public.pem' as indicators of ESXiArgs ransomware compromise. ↗
- →Check for .vmdk files renamed with a .args extension, which indicates successful ESXiArgs ransomware encryption of virtual machine disks. ↗
- ·The exact CVE used as the initial access vector for the ESXiArgs ransomware campaign is not confirmed by first-party sources; CVE-2020-3992 and CVE-2021-21974 are both listed as possibilities. ↗
- ·The OpenSLP service (port 427) is disabled by default on new ESXi installations since ESXi 7.0 U2c and ESXi 8.0 GA; exploitation requires the service to be running and port 427 reachable. ↗
- ·VMware found no evidence of an unknown 0-day being used; exploitation is attributed to known OpenSLP vulnerabilities in unpatched ESXi versions. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_msrc3.3LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-58ff-49fr-3jwf: OpenSLP as used in VMware ESXi (7
ghsa_unreviewed·2022-05-24
CVE-2020-3992 [CRITICAL] CWE-416 GHSA-58ff-49fr-3jwf: OpenSLP as used in VMware ESXi (7
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.
VulnCheck
VMware ESXi OpenSLP Use-After-Free Vulnerability
vulncheck·2020·CVSS 9.8
CVE-2020-3992 [CRITICAL] CWE-416 VMware ESXi OpenSLP Use-After-Free Vulnerability
VMware ESXi OpenSLP Use-After-Free Vulnerability
VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.
Affected: VMware ESXi
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.rapid7.com/blog/post/2020/11/11/vmware-esxi-openslp-remote-code-execution-vulnerability-cve-2020-3992-and-cve-2019-5544-what-you-need-to-know/; https://www.cyber.nj.gov/alerts-advisories/ransomware-groups-exploit-vmware-esxi-vulnerabilities; https://cybersecurityworks.com/blog/ransomware/darkside-the-ransomware-that-brought-a-us-pipeline-to-a-halt.html; https://securelist.com/it-threat-evolution-q1-2021/102382/; h
VulnCheck
VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
vulncheck·2019·CVSS 9.8
CVE-2019-5544 [CRITICAL] CWE-787 VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution.
Affected: VMware VMware ESXi and Horizon DaaS
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.rapid7.com/blog/post/2020/11/11/vmware-esxi-openslp-remote-code-execution-vulnerability-cve-2020-3992-and-cve-2019-5544-what-you-need-to-know/; https://www.cyber.nj.gov/alerts-advisories/ransomware-groups-exploit-vmware-esxi-vulnerabilities; https://cybersecurityworks.com/blog/ransomware/darks
CISA
VMware ESXi OpenSLP Use-After-Free Vulnerability
cisa·2021-11-03·CVSS 9.8
CVE-2020-3992 [CRITICAL] CWE-416 VMware ESXi OpenSLP Use-After-Free Vulnerability
Vulnerability: VMware ESXi OpenSLP Use-After-Free Vulnerability
Affected: VMware ESXi
VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-3992
Remediation Due Date: 2022-05-03
Microsoft
Microsoft Word Security Feature Bypass Vulnerability
vendor_msrc·2020-11-10·CVSS 3.3
CVE-2020-17020 [LOW] Microsoft Word Security Feature Bypass Vulnerability
Microsoft Word Security Feature Bypass Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft Office: Microsoft Office
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Click to Run
Reference: https://www.microsoft.com/download/details.aspx?familyid=af00e20b-3992-43a5-b2ad-3fd9bb018bc5
Reference: https://www.microsoft.com/download/details.aspx?familyid=7c42ef03-4cad-4897-9336-1be5d0b48678
Reference: https://www.microsoft.com/download/details.aspx?familyid=33fa0817-53a2-4938-8e74-fb6fa2d44911
Reference
VMware
VMware ESXi, Workstation, Fusion and NSX-T updates address multiple security vulnerabilities (CVE-2020-3981, CVE-2020-3982, CVE-2020-3992, CVE-2020-3993, CVE-2020-3994, CVE-2020-3995)
vendor_vmware·2020-10-20·CVSS 5.8
CVE-2020-3981 [MEDIUM] VMware ESXi, Workstation, Fusion and NSX-T updates address multiple security vulnerabilities (CVE-2020-3981, CVE-2020-3982, CVE-2020-3992, CVE-2020-3993, CVE-2020-3994, CVE-2020-3995)
VMSA-2020-0023: VMware ESXi, Workstation, Fusion and NSX-T updates address multiple security vulnerabilities (CVE-2020-3981, CVE-2020-3982, CVE-2020-3992, CVE-2020-3993, CVE-2020-3994, CVE-2020-3995)
OpenSLP as used in ESXi has a use-after-free issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVEs: CVE-2020-3981, CVE-2020-3982, CVE-2020-3992, CVE-2020-3993, CVE-2020-3994, CVE-2020-3995
Affected products: Fusion Pro, NSX-T, VMware Cloud Foundation, VMware ESXi, VMware Fusion, VMware NSX, VMware Workstation, VMware vCenter Server, VMware vSphere, Workstation Player, Workstation Pro
No detection rules found.
No public exploits indexed.
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
#### Table of Contents
- Who is LockBit? How it Evolved and Operates
- Monero: The Coin of the Realm
- Patch or Mitigate Now: Critical CVEs Exploited by LockBit
- Beyond Traditional Endpoints: Other Compromised Systems
- Initial Access and Deployment
- Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
## Table of Contents
Who is LockBit? How it Evolved and Operates
Monero: The Coin of the Realm
Patch or Mitigate Now: Critical CVEs Exploited by LockBit
Beyond Traditional Endpoints: Other Compromised Systems
Initial Access and Deployment
Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will leverage
Qualys
Ransomware Targets Outdated VMware ESXi Hypervisors: Protect Your Systems Now! | Qualys
blogs_qualys·2023-02-08·CVSS 9.8
[CRITICAL] Ransomware Targets Outdated VMware ESXi Hypervisors: Protect Your Systems Now! | Qualys
#### Table of Contents
- Qualys QID Coverage
- Discover Vulnerable VMwares ESXi Using Qualys VMDR
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- ESXiArgs-Recover: A Solution for Ransomware Attacks on VMware ESXi Hypervisors
- Conclusion
- Contributors
Updated on February 8, 2023 at 2:40 PM Pacific Standard Time: This article has been updated with EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Updated on February 7, 2023 at 9:05 PM Pacific Standard Time: This article has been updated with the latest information on the ESXiArgs-Recovery Solution, a script offered by the Cybersecurity and Infrastructure Security Agency (CISA) for accessing encrypted virtual machines.
We wanted to bring to your attention a significant ransomware threat recently repor
Qualys
Ransomware Targets Outdated VMware ESXi Hypervisors: Protect Your Systems Now!
blogs_qualys·2023-02-08·CVSS 9.8
[CRITICAL] Ransomware Targets Outdated VMware ESXi Hypervisors: Protect Your Systems Now!
## Table of Contents
Qualys QID Coverage
Discover Vulnerable VMwares ESXi Using Qualys VMDR
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
ESXiArgs-Recover: A Solution for Ransomware Attacks on VMware ESXi Hypervisors
Conclusion
Contributors
Updated on February 8, 2023 at 2:40 PM Pacific Standard Time: This article has been updated with EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Updated on February 7, 2023 at 9:05 PM Pacific Standard Time: This article has been updated with the latest information on the ESXiArgs-Recovery Solution, a script offered by the Cybersecurity and Infrastructure Security Agency (CISA) for accessing encrypted virtual machines.
We wanted to bring to your attention a significant ransomware threat recently reported in th
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
# Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative
2022/07/27
Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service, VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c. In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/IP s
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
## Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative 2022/07/27 Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service , VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c . In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/IP
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
## Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative Jul 27, 2022 Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service , VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c . In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/
Securelist
Cyberthreats to financial organizations in 2022
blogs_securelist·2021-11-23
Cyberthreats to financial organizations in 2022
Table of Contents
Analysis of forecasts for 2021
Key events in 2021
Forecasts for 2022
Authors
Dmitry Bestuzhev
Santiago Pontiroli
Fabio Assolini
Seongsu Park
## A look back on the year 2021 and what to expect in 2022
First of all, we are going to analyze the forecasts we made at the end of 2020 and see how accurate they were. Then we will go through the key events of 2021 relating to attacks on financial organizations. Finally, we will make some forecasts about financial attacks in 2022.
## Analysis of forecasts for 2021
The COVID-19 pandemic is likely to cause a massive wave of poverty, and that invariably translates into more people resorting to crime, including cybercrime. We might see certain economies crashing and local currencies plummeting, which would make Bitcoin thef
Qualys
DarkSide Ransomware
blogs_qualys·2021-06-09·CVSS 9.8
[CRITICAL] DarkSide Ransomware
## Table of Contents
About DarkSide Ransomware
Technical Details
Vulnerabilities Exploited
Detection, Mitigation or Additional Important Safety Measures
DarkSide Ransomware TTP Map
Exploited Vulnerabilities
IOCs
References
DarkSide ransomware is a relatively new ransomware strain that threat actors have been using to target multiple large, high-revenue organizations resulting in the encryption and theft of sensitive data and threats to make it publicly available if the ransom demand is not paid. Because of its potential impact, we detail here the mechanisms used by the ransomware so that security teams can better assess their risk. We also recommend best practices to reduce the risk of a successful attack.
## About DarkSide Ransomware
DarkSide ransomware, first seen in August 20
Qualys
DarkSide Ransomware | Qualys
blogs_qualys·2021-06-09·CVSS 9.8
[CRITICAL] DarkSide Ransomware | Qualys
#### Table of Contents
- About DarkSide Ransomware
- Technical Details
- Vulnerabilities Exploited
- Detection, Mitigation or Additional Important Safety Measures
- DarkSide Ransomware TTP Map
- Exploited Vulnerabilities
- IOCs
- References
DarkSide ransomware is a relatively new ransomware strain that threat actors have been using to target multiple large, high-revenue organizations resulting in the encryption and theft of sensitive data and threats to make it publicly available if the ransom demand is not paid. Because of its potential impact, we detail here the mechanisms used by the ransomware so that security teams can better assess their risk. We also recommend best practices to reduce the risk of a successful attack.
## About DarkSide Ransomware
DarkSide ransomware, first seen i
Securelist
IT threat evolution Q1 2021
blogs_securelist·2021-05-31
IT threat evolution Q1 2021
Table of Contents
- Targeted attacks
- Other malware
Authors
- David Emm
## Targeted attacks
### Putting the ‘A’ into APT
In December, SolarWinds, a well-known IT managed services provider, fell victim to a sophisticated supply-chain attack. The company’s Orion IT, a solution for monitoring and managing customers’ IT infrastructure, was compromised by threat actors. This resulted in the deployment of a custom backdoor, named Sunburst, on the networks of more than 18,000 SolarWinds customers, including many large corporations and government bodies, in North America, Europe, the Middle East and Asia.
One thing that sets this campaign apart from others, is the peculiar victim profiling and validation scheme. Out of the 18,000 Orion IT customers affected by the malware, it seems that on
Checkpoint
26th October – Threat Intelligence Bulletin
blogs_checkpoint·2020-10-26
CVE-2020-3118 26th October – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 26th October – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 26th October 2020, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Voter database in Hall Country, Georgia, used to verify voter signatures, has been breached by ransomware, alongside other government systems. This might be the first official election resource to be hit by ransomware. The ‘DoppelPaymer’ gang has claimed responsibility for the attack.
US officials warn against a R
Recorded Future
ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers
blogs_recorded_future·CVSS 9.8
CVE-2021-21974 [CRITICAL] ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers
# ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers
An ongoing ransomware campaign dubbed ESXiArgs is targeting outdated VMware ESXi installations. While first reports surfaced on Friday, February 3rd, a more significant wave infected at least 2,000 hosts over the weekend, according to BleepingComputer. An internet-wide scan reported up to 8,000 infected hosts as of this writing.
The attack likely exploits CVE-2021-21974, a two-year-old remote code execution vulnerability in the bundled OpenSLP service, for which a patch has been available since February 2021.
VMware ESXi is a Type 1 hypervisor that runs directly on host server hardware, providing a virtualization layer capable of abstracting CPU, storage, memory, and networking resources into multiple virtual machines.
Crowdstrike
Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Greynoiseio
GreyNoise
blogs_greynoiseio·CVSS 8.8
[HIGH] GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Crowdstrike
Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Recorded Future
ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers | Recorded Future
blogs_recorded_future·CVSS 9.8
CVE-2021-21974 [CRITICAL] ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers | Recorded Future
## ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers
An ongoing ransomware campaign dubbed ESXiArgs is targeting outdated VMware ESXi installations. While first reports surfaced on Friday, February 3rd, a more significant wave infected at least 2,000 hosts over the weekend, according to BleepingComputer . An internet-wide scan reported up to 8,000 infected hosts as of this writing.
The attack likely exploits CVE-2021-21974, a two-year-old remote code execution vulnerability in the bundled OpenSLP service, for which a patch has been available since February 2021.
VMware ESXi is a Type 1 hypervisor that runs directly on host server hardware, providing a virtualization layer capable of abstracting CPU, storage, memory, and networking resources into multiple virtual machines
https://www.vmware.com/security/advisories/VMSA-2020-0023.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-20-1377/https://www.zerodayinitiative.com/advisories/ZDI-20-1385/https://www.vmware.com/security/advisories/VMSA-2020-0023.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-20-1377/https://www.zerodayinitiative.com/advisories/ZDI-20-1385/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3992
2020-10-20
Published
2021-11-03
Added to CISA KEV
Exploited in the wild