CVE-2020-3952

Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.

  • Published Apr 10, 2020
  • CVSS 9.8 critical
  • 90.4% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • Public exploit code is available

Affected software

CVE-2020-3952 at the National Vulnerability Database