ZeroHour

CVE-2019-5544

KEV ransomwaremass

Heap-Based Buffer Overflow in OpenSLP Used by VMware ESXi and Horizon DaaS

CISA: VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability

CVSS 3.1
9.8 critical
EPSS
97%p100
Published
()
KEV added
AI analysis

CVE-2019-5544 is a heap-based buffer overflow (CWE-787, heap overwrite) in the OpenSLP service shipped with VMware ESXi and the Horizon DaaS appliances, rated Critical at CVSSv3 9.8 by VMware. The flaw is reachable through the network-facing Service Location Protocol service with no authentication, privileges, or user interaction (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), so a remote attacker can trigger the heap overwrite with high confidentiality, integrity, and availability impact — in practice, remote code execution on the affected host. Organizations running affected ESXi builds or Horizon DaaS appliances are directly exposed, and CPE data also ties the flaw to upstream OpenSLP and Red Hat Enterprise Linux/Fedora packages that ship it. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use and EPSS puts its 30-day exploitation probability at 97.3%. Related reporting describes criminals exploiting VMware ESXi flaws to encrypt VM disks and a previously undetected ESXi backdoor, and no public PoC is catalogued.

What to do: Apply updates per vendor instructions — the CISA KEV required action — for ESXi, Horizon DaaS, and any affected OpenSLP packages from Red Hat/Fedora. As an interim mitigation, restrict or disable the SLP service (TCP/UDP port 427) on ESXi hosts and avoid exposing management interfaces to the internet. Given known ransomware use since the 2021-11-03 KEV listing, hunt for signs of compromise on any unpatched ESXi hosts.

Affected
VMware ESXi
VMware Horizon DaaS (appliance)
OpenSLP (upstream)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server EUS
Red Hat Enterprise Linux Server AUS
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM Z Systems
Red Hat Enterprise Linux for IBM Z Systems EUS
Red Hat Enterprise Linux for Power Big Endian
Red Hat Enterprise Linux for Power Big Endian EUS
Red Hat Enterprise Linux for Power Little Endian
Estimated exposure
masshundreds of thousands to millions of ESXi hosts deployed; tens of thousands internet-exposed with the SLP service (port 427) reachable — VMware ESXi is among the most widely deployed hypervisors with an installed base on the order of 10^5–10^6 hosts, public internet scans have shown tens of thousands of hosts exposing SLP, and ransomware actors have repeatedly reached ESXi…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

CISA Known Exploited Vulnerability
Affected
VMware VMware ESXi and Horizon DaaS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
vmwareredhatopenslpfedoraproject
Products
horizon daas, esxi, enterprise linux desktop, enterprise linux for ibm z systems, enterprise linux for ibm z systems eus, enterprise linux for power big endian, enterprise linux for power big endian eus, enterprise linux for power little endian, enterprise linux for power little endian eus, enterprise linux server, enterprise linux server aus, enterprise linux server eus
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news