VMware addresses ESXi issue disclosed at the Tianfu Cup competition
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-5544 | Heap-Based Buffer Overflow in OpenSLP Used by VMware ESXi and Horizon DaaS CVE-2019-5544 is a heap-based buffer overflow (CWE-787, heap overwrite) in the OpenSLP service shipped with VMware ESXi and the Horizon DaaS appliances, rated Critical at CVSSv3 9.8 by VMware. The flaw is reachable through the network-facing Service Location Protocol service with no authentication, privileges, or user interaction (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), so a remote attacker can trigger the heap overwrite with high confidentiality, integrity, and availability impact — in practice, remote code execution on the affected host. Organizations running affected ESXi builds or Horizon DaaS appliances are directly exposed, and CPE data also ties the flaw to upstream OpenSLP and Red Hat Enterprise Linux/Fedora packages that ship it. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use and EPSS puts its 30-day exploitation probability at 97.3%. Related reporting describes criminals exploiting VMware ESXi flaws to encrypt VM disks and a previously undetected ESXi backdoor, and no public PoC is catalogued. Do: Apply updates per vendor instructions — the CISA KEV required action — for ESXi, Horizon DaaS, and any affected OpenSLP packages from Red Hat/Fedora. As an interim mitigation, restrict or disable the SLP service (TCP/UDP port 427) on ESXi hosts and avoid exposing management interfaces to the internet. Given known ransomware use since the 2021-11-03 KEV listing, hunt for signs of compromise on any unpatched ESXi hosts. | 9.8 | 97% | KEV ransomware |
| masshundreds of thousands to millions of ESXi hosts deployed; tens of thousands internet-exposed with the SLP service (port 427) reachable |
Full article348 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 06, 2019
![]()
VMware has addressed a critical remote code execution vulnerability in ESXi that was disclosed recently at the Tianfu Cup hacking competition.
This week VMware has released security updates that fix a critical remote code execution vulnerability in ESXi that was recently disclosed by white hat hackers at the Tianfu Cup hacking competition in China.
The Tianfu Cup 2019 International Cyber Security Competition took place in November, white hat hackers that participated into the competition have earned $545,000 for working zero-day exploits.
Researcher @xiaowei from the 360Vulcan team received the highest reward ($200,000) for a working exploit for the VMware vSphere ESXi product that allowed them to escape from the guest virtual machine to the host. The critical flaw tracked as CVE-2019-5544 has been assigned a CVSS score of 9.8.
The hacker was able to take control of the host operating system in only 24 seconds.
According to VMware, the CVE-2019-5544 flaw is a heap overwrite issue that resides in the OpenSLP open-source implementation of the Service Location Protocol (SLP), which allows the software to locate resources on a network.
“OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.” reads the advisory published by the company..
“A malicious actor with network access to port 427 on an ESXi host or on any Horizon DaaS management appliance may be able to overwrite the heap of the OpenSLP service resulting in remote code execution,”
Experts from VMware that were present at the competition received the details of the exploit immediately after the expert demonstrated the attack.
According to VMware, the flaw affects ESXi versions 6.0, 6.5 and 6.7 running on any platform, and the Horizon cloud desktop-as-a-service (DaaS) platform version 8.x.
The company has already patched the issue for ESXi and it is currently working on a fix for Horizon DaaS.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – VMWare, hacking)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/94787/hacking/vmware-fixes-esxi-flaw.html