peter bassill · operator
$ cve CVE-2019-5544 JSON

CVE-2019-5544 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 97.3% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS97.26% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2022-05-03
Public exploitnone known
Published2019-12-06
Last modified2026-06-17

CISA KEV

NameVMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productVMware / VMware ESXi and Horizon DaaS
Ransomware useknown

Affected (16)

VendorProduct
fedoraprojectfedora
openslpopenslp
redhatenterprise linux desktop
redhatenterprise linux for ibm z systems
redhatenterprise linux for ibm z systems eus
redhatenterprise linux for power big endian
redhatenterprise linux for power big endian eus
redhatenterprise linux for power little endian
redhatenterprise linux for power little endian eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation
vmwareesxi
vmwarehorizon daas

References

→ the Explorer  ·  watch your stack  ·  NVD