Heap Overflow Vulnerability in OpenSLP of VMware ESXi and Horizon DaaS Appliances
CVE-2019-5544
Key Information:
- Vendor
- Vmware
- Status
- Vendor
- CVE Published:
- 6 December 2019
Badges
Summary
OpenSLP utilized in VMware ESXi and Horizon DaaS appliances has a critical heap overflow vulnerability. This issue can lead to severe consequences, including remote code execution. Attackers can exploit this flaw to potentially manipulate or corrupt memory, enabling unauthorized access and executing arbitrary code. It is crucial for organizations using affected versions of OpenSLP to apply the recommended patches to mitigate risks associated with this vulnerability.
CISA Reported
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed as being exploited and is known by the CISA as enabling ransomware campaigns.
The CISA's recommendation is: Apply updates per vendor instructions.
Affected Version(s)
ESXi and Horizon DaaS ESXi 6.7 prior to patch release ESXi670-201912001, ESXi 6.5 prior to patch release ESXi650-201912001, ESXi 6.0 prior to patch release ESXi600-201912001 and Horizon DaaS 8.x prior to BZ-2467224-Disable_SLPD_service_permanently_801_Hotfix.
References
EPSS Score
87% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 💰
Used in Ransomware
- 👾
Exploit known to exist
- 🦅
CISA Reported
Vulnerability published
Vulnerability Reserved