Vulnerability Intelligence Report
VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
CVE-2019-5544
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:96.82%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-787 ↗CWE-787 Out-of-bounds Write
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| vmware | horizon_daas | all |
| vmware | esxi | 6.0, 6.5, 6.7 |
| redhat | enterprise_linux_desktop | 6.0, 7.0 |
| redhat | enterprise_linux_for_ibm_z_systems | 6.0_s390x, 7.0_s390x |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 7.7_s390x |
| redhat | enterprise_linux_for_power_big_endian | 6.0_ppc64, 7.0_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.7_ppc64 |
| redhat | enterprise_linux_for_power_little_endian | 7.0_ppc64le |
| redhat | enterprise_linux_for_power_little_endian_eus | 7.7_ppc64le |
| redhat | enterprise_linux_server | 6.0, 7.0 |
| redhat | enterprise_linux_server_aus | 7.7 |
| redhat | enterprise_linux_server_eus | 7.7 |
| redhat | enterprise_linux_server_tus | 7.7 |
| redhat | enterprise_linux_workstation | 6.0, 7.0 |
| openslp | openslp | all |
| fedoraproject | fedora | 30, 31 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
96.823%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VMware by Broadcom · Vendor · USA |
| Reserved | 2019-01-07T00:00:00 |
| Published | 2019-12-06T15:54:18 |
| Last Updated | 2025-10-21T23:35:56 |
Community Chatter & Buzz