Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
VMware vCenter
Exploit
CVE-2020-3952
NVD
Refer to CVE-2020-3952 NVD advisory