CVE-2019-5544
VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
Record summary
CVE-2019-5544 has a selected CVSS score of 9.8 (critical); EIP currently links 2 repository PoCs and 1 Nuclei template. CISA lists CVE-2019-5544 in KEV and reports its use in known ransomware campaigns.
Description
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 3, 2021 · CISA
- VulnCheck KEV
- Listed · Nov 11, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · CISA
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
VMware ESXi and Horizon DaaSBrowse VMware / VMware ESXi and Horizon DaaS | CISA | Version data not supplied | |
ESXi and Horizon DaaS | CVE List | ESXi 6.7 prior to patch release ESXi670-201912001, ESXi 6.5 prior to patch release ESXi650-201912001, ESXi 6.0 prior to patch release ESXi600-201912001 and Horizon DaaS 8.x prior to BZ-2467224-Disable_SLPD_service_permanently_801_Hotfix. | affected |
Proofs of concept
2Repository PoCs
GitHubHynekPetrak/CVE-2019-5544_CVE-2020-3992Repository PoCby HynekPetrakStars: 49Not analyzed4 files
GitHubdgh05t/VMware_ESXI_OpenSLP_PoCsRepository PoCby dgh05tStars: 67Not analyzed3 files
Nuclei templates
1ProjectDiscoveryCRITICALVMware ESXi SLP - Heap Overflow DoSCVSS 9.8
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
Impact
Unauthenticated attackers can exploit heap overflow in OpenSLP implementation on ESXi and Horizon DaaS appliances to cause denial of service or potentially execute arbitrary code on VMware infrastructure servers.
Remediation
Apply VMware security patches that address the OpenSLP heap overflow vulnerability in ESXi and Horizon DaaS appliances as documented in VMware security advisories.
Source: ProjectDiscovery