Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
Published: 2020-04-10
VMware patches a critical information disclosure flaw in vCenter Server with a CVSSv3 score of 10.0. Background On April 9, VMware published VMSA-2020-0006, a security advisory for a critical vulnerability in vCenter Server that received the maximum CVSSv3 score of 10.0.
https://github.com/virtualcvcell/Exploit
https://github.com/Fa1c0n35/vmware_vcenter_cve_2020_3952
https://github.com/guardicore/vmware_vcenter_cve_2020_3952
https://www.vmware.com/security/advisories/VMSA-2020-0006
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3952
http://packetstormsecurity.com/files/157896/VMware-vCenter-Server-6.7-Authentication-Bypass.html