CVE-2019-5544
KEV ransomwaremassHeap-Based Buffer Overflow in OpenSLP Used by VMware ESXi and Horizon DaaS
CISA: VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
CVE-2019-5544 is a heap-based buffer overflow (CWE-787, heap overwrite) in the OpenSLP service shipped with VMware ESXi and the Horizon DaaS appliances, rated Critical at CVSSv3 9.8 by VMware. The flaw is reachable through the network-facing Service Location Protocol service with no authentication, privileges, or user interaction (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), so a remote attacker can trigger the heap overwrite with high confidentiality, integrity, and availability impact — in practice, remote code execution on the affected host. Organizations running affected ESXi builds or Horizon DaaS appliances are directly exposed, and CPE data also ties the flaw to upstream OpenSLP and Red Hat Enterprise Linux/Fedora packages that ship it. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use and EPSS puts its 30-day exploitation probability at 97.3%. Related reporting describes criminals exploiting VMware ESXi flaws to encrypt VM disks and a previously undetected ESXi backdoor, and no public PoC is catalogued.
What to do: Apply updates per vendor instructions — the CISA KEV required action — for ESXi, Horizon DaaS, and any affected OpenSLP packages from Red Hat/Fedora. As an interim mitigation, restrict or disable the SLP service (TCP/UDP port 427) on ESXi hosts and avoid exposing management interfaces to the internet. Given known ransomware use since the 2021-11-03 KEV listing, hunt for signs of compromise on any unpatched ESXi hosts.
| VMware ESXi | — |
| VMware Horizon DaaS (appliance) | — |
| OpenSLP (upstream) | — |
| Red Hat Enterprise Linux Server | — |
| Red Hat Enterprise Linux Server EUS | — |
| Red Hat Enterprise Linux Server AUS | — |
| Red Hat Enterprise Linux Desktop | — |
| Red Hat Enterprise Linux for IBM Z Systems | — |
| Red Hat Enterprise Linux for IBM Z Systems EUS | — |
| Red Hat Enterprise Linux for Power Big Endian | — |
| Red Hat Enterprise Linux for Power Big Endian EUS | — |
| Red Hat Enterprise Linux for Power Little Endian | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
- Affected
- VMware VMware ESXi and Horizon DaaS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- vmwareredhatopenslpfedoraproject
- Products
- horizon daas, esxi, enterprise linux desktop, enterprise linux for ibm z systems, enterprise linux for ibm z systems eus, enterprise linux for power big endian, enterprise linux for power big endian eus, enterprise linux for power little endian, enterprise linux for power little endian eus, enterprise linux server, enterprise linux server aus, enterprise linux server eus
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H