LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-5544: VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-5544 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the…

CVE-2019-5544 is a heap-based buffer overflow in the OpenSLP service used by VMware ESXi and Horizon Desktop as a Service (DaaS). An attacker who can reach the service on the network can overwrite heap memory and achieve remote code execution. This matters because ESXi hosts are foundational to many virtualization environments; successful exploitation can give an attacker a foothold on the hypervisor layer. The vulnerability has been used by ransomware operators, so unpatched systems remain a high-priority risk.

Defenders should treat any internet- or broadly network-reachable OpenSLP endpoint on these products as exposed until they confirm the vendor fix is applied. Specifics of affected builds and exact patch identifiers must be confirmed against the vendor advisory.

How it works

The weakness is classified as CWE-787 (out-of-bounds write). OpenSLP implements the Service Location Protocol and listens for network requests. The flaw allows a crafted request to overflow a heap buffer inside the OpenSLP process. By controlling what is written past the intended buffer bounds, an attacker can corrupt heap metadata or adjacent objects and divert execution flow to attacker-controlled code.

According to the CISA summary, the attacker needs network access to port 427—the port commonly associated with SLP. No authentication requirement is described in the provided facts, so the attack surface is the reachable OpenSLP service itself. Exact packet structure, heap layout details, and exploit reliability vary by build and configuration; those mechanics are not specified here and must be taken from the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

VMware ESXi is typically deployed as the bare-metal hypervisor in on-premises and private-cloud clusters. Horizon DaaS appears in desktop-as-a-service deployments that rely on the same OpenSLP component. Inventory every ESXi host and Horizon DaaS instance, including nested or lab systems that may still be reachable.

If OpenSLP has already been disabled or removed per prior hardening guidance, verify that the service is truly absent and that no residual listener remains.

How to remediate

Patch first. Apply the updates VMware released for ESXi and Horizon DaaS exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; follow that sequence and validate that the OpenSLP component is at a fixed level afterward.

If you can't patch immediately

Until the vendor update can be installed, apply compensating controls that limit reachability and increase detection.

If your data may have been exposed

Actively exploited vulnerabilities, including those known to be used by ransomware, frequently precede broader compromise and data theft. If you have evidence of exploitation or cannot rule it out, follow your incident-response plan: isolate affected hosts, preserve memory and disk images where feasible, rotate credentials that may have been accessible from the hypervisor, and assess guest workloads for secondary intrusion. You can also run a free exposure scan of your email addresses to check whether associated accounts appear in known breach datasets, which may help prioritize further credential hygiene.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVMware · VMware ESXi and Horizon DaaS
WeaknessCWE-787
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities