Record summary

CVE-2019-5544 has a selected CVSS score of 9.8 (critical); EIP currently links 2 repository PoCs and 1 Nuclei template. CISA lists CVE-2019-5544 in KEV and reports its use in known ransomware campaigns.

Description

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 3, 2021 · CISA
VulnCheck KEV
Listed · Nov 11, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · CISA

Available material

Repository PoCs
2
Nuclei templates
1

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CISAVersion data not supplied

ESXi and Horizon DaaS

CVE ListESXi 6.7 prior to patch release ESXi670-201912001, ESXi 6.5 prior to patch release ESXi650-201912001, ESXi 6.0 prior to patch release ESXi600-201912001 and Horizon DaaS 8.x prior to BZ-2467224-Disable_SLPD_service_permanently_801_Hotfix.affected

Proofs of concept

2

Repository PoCs

GitHubHynekPetrak/CVE-2019-5544_CVE-2020-3992Repository PoCby HynekPetrakStars: 49Not analyzed4 files

23.2 KiB · linked to 3 vulnerabilities

GitHub

PoC details
GitHubdgh05t/VMware_ESXI_OpenSLP_PoCsRepository PoCby dgh05tStars: 67Not analyzed3 files

3.4 KiB · linked to 2 vulnerabilities

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALVMware ESXi SLP - Heap Overflow DoSCVSS 9.8

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

Impact

Unauthenticated attackers can exploit heap overflow in OpenSLP implementation on ESXi and Horizon DaaS appliances to cause denial of service or potentially execute arbitrary code on VMware infrastructure servers.

Remediation

Apply VMware security patches that address the OpenSLP heap overflow vulnerability in ESXi and Horizon DaaS appliances as documented in VMware security advisories.

WeaknessesCWE-787
Authorsriteshs4hu
Template tagscvecve2019vmwareesxiheap-basedbufferoverflowkevdosintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:vmware:horizon_daas:*:*:*:*:*:*:*:*
Shodan: http.title:"horizon daas"
FOFA: title="horizon daas"
Google: intitle:"horizon daas"

Source: ProjectDiscovery

References

12