CVE-2020-3992 is a critical use-after-free vulnerability in the OpenSLP service used by VMware ESXi. The flaw is triggered during processing of SLP messages and stems from improper object lifetime handling, allowing operations on memory after the associated object has been freed. A remote attacker on the management network with access to the ESXi host's SLP service on port 427 can exploit the issue without authentication. Successful exploitation can result in remote code execution in the context of the SLP daemon. Affected versions include VMware ESXi 7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, and 6.5 before ESXi650-202010401-SG.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains two Python proof-of-concept (PoC) exploits targeting VMware ESXi's OpenSLP service vulnerabilities: CVE-2019-5544 and CVE-2020-3992. The structure is simple, with two main Python scripts (CVE_2019_5544.py and CVE_2020_3992.py) and a README.md. Each script constructs custom SLP protocol packets and sends them over TCP to port 427 of a specified target IP address (default: 192.168.110.129). The payloads are designed to trigger heap overflows or other memory corruption issues in the OpenSLP service, as described in the respective CVEs. The README provides brief usage notes and mentions that the PoCs were tested on ESXi installed in VMware Workstation. The scripts do not provide post-exploitation capabilities such as shell access; they are intended to demonstrate the vulnerabilities' existence and potential for service disruption. The repository is suitable for researchers or administrators seeking to test for these specific vulnerabilities in their ESXi environments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.