CVE-2020-3952: VMware vCenter Server Information Disclosure Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 90.4% chance of exploitation in the next 30 days.

Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.

Affected products

  • VMware vCenter Server: version 6.7 only

Published 2020-04-10. Last modified 2026-06-17.