Junglewise Threat Intelligence

CVE-2019-5544: VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability

CVE-2019-5544 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Vmware Esxi. Vendors: VMware.

Executive brief

A heap-based buffer overflow vulnerability in the OpenSLP service, as used in VMware ESXi and Horizon DaaS, allows a remote attacker with network access to port 427 to overwrite the heap. This can lead to remote code execution on the affected host.

Affected products

  • VMware ESXi
  • VMware Horizon Desktop as a Service (DaaS) appliances
  • OpenSLP OpenSLP

Timeline

  • 2019-12-10: disclosed: Initial disclosure via VMware advisory VMSA-2019-0022 and mailing lists.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: disclosed: NVD publication date.