CVE-2019-5544 is a critical heap overwrite vulnerability in OpenSLP, affecting VMware ESXi and Horizon DaaS appliances, as well as products from Fedora and Red Hat. With a CVSSv3 score of 9.8, it allows unauthenticated remote attackers to execute arbitrary code with high impact on confidentiality, integrity, and availability. This vulnerability is actively exploited, notably by ransomware campaigns like ESXiArgs, and has garnered significant community discussion and media coverage, despite no public Metasploit or ExploitDB modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 9.0.0.0CPE matchmatch criteria | cpe:2.3:a:vmware:horizon_daas:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:6.0:-:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:6.0:1:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:6.0:1a:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:6.0:1b:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2019-5544
Jun 11, 2024OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
Dec 10, 2019openslp: Heap-based buffer overflow in ProcessSrvRqst() in slpd_process.c leading to remote code execution
Dec 6, 2019