cbcvebase.
CVE-2020-3992
published 2020-10-20

CVE-2020-3992: OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free…

PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
83.02%
99.6th percentile
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.

Affected

14 ranges
VendorProductVersion rangeFixed in
msrcmicrosoft_365_apps_for_enterprise_for_32-bit_systems
msrcmicrosoft_365_apps_for_enterprise_for_64-bit_systems
msrcmicrosoft_office_2010_service_pack_2
msrcmicrosoft_office_2019_for_32-bit_editions
msrcmicrosoft_office_2019_for_64-bit_editions
msrcmicrosoft_word_2010_service_pack_2
msrcmicrosoft_word_2013_rt_service_pack_1
msrcmicrosoft_word_2013_service_pack_1
msrcmicrosoft_word_2016
vmwarecloud_foundation>= 3.0 < 3.10.1.23.10.1.2
vmwarecloud_foundation>= 4.0 < 4.1.0.14.1.0.1
vmwareesxi
vmwareesxi
vmwareesxi

Detection & IOCsextracted from sources · hover to see the quote

port427
path/tmp/encrypt
path/tmp/encrypt.sh
path/tmp/public.pem
hash12ee27f56ec8a2a3eb2fe69179be3f7a7193ce2b92963ad33356ed299f7ed975
hash17139a10fd226d01738fe9323918614aa913b2a50e1a516e95cced93fa151c61
hash43e61519be440115eeaa3738a0e4aa4bb3c8ac5f9bdfce1a896db17a374eb8aa
hashafb22b1ff281c085b60052831ead0a0ed300fac0160f87851dacc67d4e158178
hashf764c49daffdacafa94aaece1d5094e0fac794639758e673440329b02c0fda39
ip45.112.240.81
ip77.243.181.196
  • Monitor for inbound TCP connections to port 427 (OpenSLP) on ESXi hosts, especially from hosts outside the management network, as this is the attack entry point for CVE-2020-3992 exploitation.
  • Check ESXi hosts in /tmp for the presence of files named 'encrypt', 'encrypt.sh', and 'public.pem' as indicators of ESXiArgs ransomware compromise.
  • Check for .vmdk files renamed with a .args extension, which indicates successful ESXiArgs ransomware encryption of virtual machine disks.
  • ·The exact CVE used as the initial access vector for the ESXiArgs ransomware campaign is not confirmed by first-party sources; CVE-2020-3992 and CVE-2021-21974 are both listed as possibilities.
  • ·The OpenSLP service (port 427) is disabled by default on new ESXi installations since ESXi 7.0 U2c and ESXi 8.0 GA; exploitation requires the service to be running and port 427 reachable.
  • ·VMware found no evidence of an unknown 0-day being used; exploitation is attributed to known OpenSLP vulnerabilities in unpatched ESXi versions.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_msrc3.3LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.