CVE-2020-3952 is an improper access-control vulnerability in vmdir, the VMware directory service shipped with VMware vCenter Server in embedded or external Platform Services Controller deployments. Under certain conditions, vmdir does not correctly enforce access controls, enabling network-reachable disclosure of sensitive directory information. Affected deployments include vCenter Server 6.7 embedded and external PSC installations through 6.7u3f, including systems upgraded from 6.0 or 6.5; fresh vCenter Server 6.7 installations are not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains a single Metasploit auxiliary module targeting VMware vCenter Server's vmdir service (modules/auxiliary/admin/ldap/vmware_vcenter_vmdir_auth_bypass.rb). The module exploits CVE-2020-3952, an authentication bypass vulnerability in vmdir, to add an arbitrary administrator user to the vCenter Server's LDAP directory. The exploit is effective against vCenter Server 6.7 instances that were upgraded from previous versions (6.0 or 6.5) and have not been patched to 6.7U3f or later. The module connects to the vmdir LDAP service (default port 636, SSL/TLS), attempts to bypass authentication, and then creates a new user with attacker-supplied credentials, adding it to the Administrators group. The code is written in Ruby and is designed to be run within the Metasploit framework. The only file in the repository is the exploit module itself, and it is fully operational, providing a direct method for privilege escalation on vulnerable vCenter Server instances.
This repository contains a single Metasploit auxiliary module targeting VMware vCenter Server's vmdir service (modules/auxiliary/gather/vmware_vcenter_vmdir_ldap.rb). The module exploits CVE-2020-3952, an information disclosure vulnerability present in vCenter Server 6.7 prior to 6.7U3f (if upgraded from 6.0 or 6.5). It connects to the vmdir LDAP service (typically over LDAPS on port 636), attempts an anonymous bind (or uses provided credentials), and dumps all LDAP data, including sensitive attributes such as userPassword and vmwSTSPrivateKey. Extracted password hashes are processed and stored as credentials, and all dumped data is saved as loot. The module provides clear output on whether the target is vulnerable and what data was extracted. The code is written in Ruby and is structured as a standard Metasploit module, making it easy to use within the framework. No hardcoded IPs or domains are present; the module is designed to be configured by the user for the target environment.
This repository contains a single Python script, 'CVE-2020-3952-POC.py', which is a proof-of-concept exploit for CVE-2020-3952, a remote command injection vulnerability in VMware vCenter Server. The script takes command-line arguments for the target IP, local host, and ports, and constructs a base64-encoded payload that is executed to establish a reverse shell from the target to the attacker's machine. The exploit uses the 'requests' library to send the payload and attempts to create a raw socket for further communication. The script is operational and demonstrates remote code execution capabilities, targeting VMware vCenter Server instances vulnerable to CVE-2020-3952. The main fingerprintable endpoint is the target IP address specified by the user. The repository is structured as a single-file exploit with clear usage instructions and sample output.
This repository contains a proof-of-concept exploit for CVE-2020-3952, a critical vulnerability in VMware vCenter Server 6.7 (specifically, instances upgraded from previous versions and not cleanly installed). The exploit is implemented in a single Python script (exploit.py) that uses the python-ldap library to interact with the vCenter's LDAP service. The script first attempts an LDAP bind (expected to fail), then creates a new user in the vSphere directory, and finally adds this user to the Administrators group, granting full administrative access. The README provides usage instructions and context about the vulnerability. The only code file is exploit.py, which is the main entry point. The exploit requires network access to the vCenter's LDAP service and attacker-supplied credentials for the new user. No hardcoded payloads are present; the script takes parameters for the target IP, username, and password. The endpoints involved are the vCenter's LDAP service and specific LDAP DNs for user and group management.
This repository contains a proof-of-concept exploit for CVE-2020-3952, a critical vulnerability in VMware vCenter Server 6.7 (prior to Update 3f, only on upgraded installations). The exploit is implemented in a single Python script (exploit.py) that uses the python-ldap library to connect to the target vCenter's LDAP service. The script first attempts an LDAP bind (expected to fail), then creates a new user in the vSphere local directory, and finally adds this user to the Administrators group, granting full administrative access. The README provides background, usage instructions, and references to further documentation. The only code file is exploit.py, which is the main entry point and contains all exploit logic. No hardcoded endpoints are present; the target IP is supplied as a command-line argument. The exploit requires network access to the vCenter's LDAP service and is operational, providing a working privilege escalation payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A broken access control vulnerability in VMware vCenter Server related to LDAP that can allow unauthorized access/privilege impact.
A critical information disclosure vulnerability in VMware vCenter Server/Platform Services Controller (vmdir) that can allow a network attacker to exfiltrate sensitive information, potentially enabling compromise of vCenter Server or other services relying on vmdir for authentication.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.