CVE-2020-3992—VMware ESXi OpenSLP Use-After-Free Vulnerability
PUBLISHEDvulnerability record
2021-11-03 · last modified June 21, 2025
Metadata
Vulnerability Name
VMware ESXi OpenSLP Use-After-Free Vulnerability
Description
VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.
Known To Be Used in Ransomware Campaigns?
Action
Apply updates per vendor instructions.