CVE-2019-5544
published 2019-12-06CVE-2019-5544: OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical…
PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
96.82%
99.9th percentile
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_openslp_2.0.0-26_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_openslp_2.0.0-26_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| openslp | openslp | <= 2.0.0 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_power_big_endian | — | — |
| redhat | enterprise_linux_for_power_big_endian | — | — |
| redhat | enterprise_linux_for_power_big_endian_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for inbound TCP connections to port 427 on ESXi hosts and Horizon DaaS appliances, especially from unexpected or external sources, as this is the attack vector for CVE-2019-5544 OpenSLP heap overwrite exploitation. ↗
- →Hunt for ESXiArgs ransomware compromise by querying for HTTP responses containing the ransom note title 'How to Restore Your Files' on public-facing ESXi host IPs (Censys query: services.http.response.body: "How to Restore Your Files" and services.http.response.html_title:"How to Restore Your Files"). ↗
- →Check Point IPS signature 'VMWare OpenSLP Heap Buffer Overflow (CVE-2019-5544; CVE-2021-21974)' provides detection coverage for exploitation attempts against this vulnerability. ↗
- ·The ESXiArgs ransomware campaign's initial access CVE has not been definitively confirmed by first-party sources; CVE-2021-21974 is widely cited but VMware stated no 0-day was used, and CVE-2019-5544 / CVE-2020-3992 remain plausible alternative vectors. ↗
- ·The DarkSide ransomware SHA-256 hashes listed are associated with DarkSide payloads that exploited CVE-2019-5544 as part of their VMware ESXi attack chain, not the CVE exploit itself. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4734-5452-r5fh: OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue
ghsa_unreviewed·2022-05-24
CVE-2019-5544 [HIGH] CWE-787 GHSA-4734-5452-r5fh: OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
VulnCheck
VMware ESXi OpenSLP Use-After-Free Vulnerability
vulncheck·2020·CVSS 9.8
CVE-2020-3992 [CRITICAL] CWE-416 VMware ESXi OpenSLP Use-After-Free Vulnerability
VMware ESXi OpenSLP Use-After-Free Vulnerability
VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.
Affected: VMware ESXi
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.rapid7.com/blog/post/2020/11/11/vmware-esxi-openslp-remote-code-execution-vulnerability-cve-2020-3992-and-cve-2019-5544-what-you-need-to-know/; https://www.cyber.nj.gov/alerts-advisories/ransomware-groups-exploit-vmware-esxi-vulnerabilities; https://cybersecurityworks.com/blog/ransomware/darkside-the-ransomware-that-brought-a-us-pipeline-to-a-halt.html; https://securelist.com/it-threat-evolution-q1-2021/102382/; h
OSV
CVE-2019-5544: OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue
osv·2019-12-06·CVSS 9.8
CVE-2019-5544 [CRITICAL] CVE-2019-5544: OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
VulnCheck
VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
vulncheck·2019·CVSS 9.8
CVE-2019-5544 [CRITICAL] CWE-787 VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution.
Affected: VMware VMware ESXi and Horizon DaaS
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.rapid7.com/blog/post/2020/11/11/vmware-esxi-openslp-remote-code-execution-vulnerability-cve-2020-3992-and-cve-2019-5544-what-you-need-to-know/; https://www.cyber.nj.gov/alerts-advisories/ransomware-groups-exploit-vmware-esxi-vulnerabilities; https://cybersecurityworks.com/blog/ransomware/darks
CISA
VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
cisa·2021-11-03·CVSS 9.8
CVE-2019-5544 [CRITICAL] CWE-787 VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
Vulnerability: VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
Affected: VMware VMware ESXi and Horizon DaaS
VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-5544
Remediation Due Date: 2022-05-03
Ubuntu
OpenSLP vulnerability
vendor_ubuntu·2021-04-19
CVE-2019-5544 OpenSLP vulnerability
Title: OpenSLP vulnerability
Summary: OpenSLP could be made to crash or run programs as your login if it received
specially crafted network traffic.
It was discovered that OpenSLP did not properly validate URLs. A remote
attacker could use this issue to cause OpenSLP to crash or possibly execute
arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base scor
vendor_msrc·2019-12-10·CVSS 9.8
CVE-2019-5544 [CRITICAL] CWE-787 OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base scor
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will u
Red Hat
openslp: Heap-based buffer overflow in ProcessSrvRqst() in slpd_process.c leading to remote code execution
vendor_redhat·2019-12-06·CVSS 9.8
CVE-2019-5544 [CRITICAL] CWE-122 openslp: Heap-based buffer overflow in ProcessSrvRqst() in slpd_process.c leading to remote code execution
openslp: Heap-based buffer overflow in ProcessSrvRqst() in slpd_process.c leading to remote code execution
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
A heap overflow vulnerability was found in OpenSLP. An attacker could use this flaw to gain remote code execution.
Statement: This issue did not affect the versions of openslp as shipped with Red Hat Enterprise Linux 8 as they did not include the slpd service component.
Mitigation: There is no known mitigation.
Package: openslp (Red Hat Enterprise Linux 8) - Not affected
Package: openslp (Red Hat Enterprise Linux 9) - Not affected
VMware
VMware ESXi and Horizon DaaS updates address OpenSLP remote code execution vulnerability (CVE-2019-5544)
vendor_vmware·2019-12-05·CVSS 9.8
CVE-2019-5544 [CRITICAL] VMware ESXi and Horizon DaaS updates address OpenSLP remote code execution vulnerability (CVE-2019-5544)
VMSA-2019-0022: VMware ESXi and Horizon DaaS updates address OpenSLP remote code execution vulnerability (CVE-2019-5544)
| Advisory Severity | Critical | Synopsis | VMware ESXi and Horizon DaaS updates address OpenSLP remote code execution vulnerability (CVE-2019-5544) | Issue Date | 2019-12-05 | Updated On | 2020-05-08 | CVE(s) | CVE-2019-5544
CVEs: CVE-2019-5544
Affected products: VMware ESXi, VMware Horizon, vSphere
No detection rules found.
Nuclei
VMware ESXi SLP - Heap Overflow DoS
nuclei·CVSS 9.8
CVE-2019-5544 [CRITICAL] VMware ESXi SLP - Heap Overflow DoS
VMware ESXi SLP - Heap Overflow DoS
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
Template:
id: CVE-2019-5544
info:
name: VMware ESXi SLP - Heap Overflow DoS
author: riteshs4hu
severity: critical
description: |
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
impact: |
Unauthenticated attackers can exploit heap overflow in OpenSLP implementation on ESXi and Horizon DaaS appliances to cause denial of service or potentially execute arbitrary code on VMware infrastructu
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
#### Table of Contents
- Who is LockBit? How it Evolved and Operates
- Monero: The Coin of the Realm
- Patch or Mitigate Now: Critical CVEs Exploited by LockBit
- Beyond Traditional Endpoints: Other Compromised Systems
- Initial Access and Deployment
- Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
## Table of Contents
Who is LockBit? How it Evolved and Operates
Monero: The Coin of the Realm
Patch or Mitigate Now: Critical CVEs Exploited by LockBit
Beyond Traditional Endpoints: Other Compromised Systems
Initial Access and Deployment
Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will leverage
Checkpoint
13th February – Threat Intelligence Report
blogs_checkpoint·2023-02-13·CVSS 9.8
CVE-2019-5544 [CRITICAL] 13th February – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 13th February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 13th February, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
The California cities of Oakland and Modesto have been targeted by ransomware attacks, disrupting services in the former and the police network in the latter. Also in California, healthcare company ‘Heritage Provider Network’ has confirmed that medical and personal information of more than 3 million patients had been disc
Checkpoint
6th February – Threat Intelligence Report
blogs_checkpoint·2023-02-06
CVE-2022-31711 6th February – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 6th February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 6th February, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHE
Check Point Research has flagged the Dingo crypto Token, with a market cap of $10,941,525 as a scam. The threat actors behind the token added a backdoor function in its smart contract, to manipulate the fee. Specifically, they used the “setTaxFeePercent” function within the token’s smart contract code to manipulate the buyin
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
# Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative
2022/07/27
Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service, VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c. In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/IP s
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
## Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative 2022/07/27 Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service , VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c . In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/IP
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
## Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative Jul 27, 2022 Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service , VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c . In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/
Securelist
Cyberthreats to financial organizations in 2022
blogs_securelist·2021-11-23
Cyberthreats to financial organizations in 2022
Table of Contents
Analysis of forecasts for 2021
Key events in 2021
Forecasts for 2022
Authors
Dmitry Bestuzhev
Santiago Pontiroli
Fabio Assolini
Seongsu Park
## A look back on the year 2021 and what to expect in 2022
First of all, we are going to analyze the forecasts we made at the end of 2020 and see how accurate they were. Then we will go through the key events of 2021 relating to attacks on financial organizations. Finally, we will make some forecasts about financial attacks in 2022.
## Analysis of forecasts for 2021
The COVID-19 pandemic is likely to cause a massive wave of poverty, and that invariably translates into more people resorting to crime, including cybercrime. We might see certain economies crashing and local currencies plummeting, which would make Bitcoin thef
Qualys
DarkSide Ransomware
blogs_qualys·2021-06-09·CVSS 9.8
[CRITICAL] DarkSide Ransomware
## Table of Contents
About DarkSide Ransomware
Technical Details
Vulnerabilities Exploited
Detection, Mitigation or Additional Important Safety Measures
DarkSide Ransomware TTP Map
Exploited Vulnerabilities
IOCs
References
DarkSide ransomware is a relatively new ransomware strain that threat actors have been using to target multiple large, high-revenue organizations resulting in the encryption and theft of sensitive data and threats to make it publicly available if the ransom demand is not paid. Because of its potential impact, we detail here the mechanisms used by the ransomware so that security teams can better assess their risk. We also recommend best practices to reduce the risk of a successful attack.
## About DarkSide Ransomware
DarkSide ransomware, first seen in August 20
Qualys
DarkSide Ransomware | Qualys
blogs_qualys·2021-06-09·CVSS 9.8
[CRITICAL] DarkSide Ransomware | Qualys
#### Table of Contents
- About DarkSide Ransomware
- Technical Details
- Vulnerabilities Exploited
- Detection, Mitigation or Additional Important Safety Measures
- DarkSide Ransomware TTP Map
- Exploited Vulnerabilities
- IOCs
- References
DarkSide ransomware is a relatively new ransomware strain that threat actors have been using to target multiple large, high-revenue organizations resulting in the encryption and theft of sensitive data and threats to make it publicly available if the ransom demand is not paid. Because of its potential impact, we detail here the mechanisms used by the ransomware so that security teams can better assess their risk. We also recommend best practices to reduce the risk of a successful attack.
## About DarkSide Ransomware
DarkSide ransomware, first seen i
Securelist
IT threat evolution Q1 2021
blogs_securelist·2021-05-31
IT threat evolution Q1 2021
Table of Contents
- Targeted attacks
- Other malware
Authors
- David Emm
## Targeted attacks
### Putting the ‘A’ into APT
In December, SolarWinds, a well-known IT managed services provider, fell victim to a sophisticated supply-chain attack. The company’s Orion IT, a solution for monitoring and managing customers’ IT infrastructure, was compromised by threat actors. This resulted in the deployment of a custom backdoor, named Sunburst, on the networks of more than 18,000 SolarWinds customers, including many large corporations and government bodies, in North America, Europe, the Middle East and Asia.
One thing that sets this campaign apart from others, is the peculiar victim profiling and validation scheme. Out of the 18,000 Orion IT customers affected by the malware, it seems that on
Crowdstrike
Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Greynoiseio
GreyNoise
blogs_greynoiseio·CVSS 8.8
[HIGH] GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Crowdstrike
Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Bugzilla
CVE-2019-5544 openslp: Heap-based buffer overflow in ProcessSrvRqst() in slpd_process.c leading to remote code execution [fedora-all]
bugzilla·2019-12-06·CVSS 9.8
CVE-2019-5544 [CRITICAL] CVE-2019-5544 openslp: Heap-based buffer overflow in ProcessSrvRqst() in slpd_process.c leading to remote code execution [fedora-all]
CVE-2019-5544 openslp: Heap-based buffer overflow in ProcessSrvRqst() in slpd_process.c leading to remote code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messag
Bugzilla
CVE-2019-5544 openslp: Heap-based buffer overflow in ProcessSrvRqst() in slpd_process.c leading to remote code execution
bugzilla·2019-11-28·CVSS 9.8
CVE-2019-5544 [CRITICAL] CVE-2019-5544 openslp: Heap-based buffer overflow in ProcessSrvRqst() in slpd_process.c leading to remote code execution
CVE-2019-5544 openslp: Heap-based buffer overflow in ProcessSrvRqst() in slpd_process.c leading to remote code execution
A heap overflow vulnerability was found in openslp, that may result in remote code execution.
Discussion:
Created attachment 1640334
Patch openslp 1.2.0
---
Created attachment 1640335
Patch openslp 2.0.0
---
Public via:
https://seclists.org/oss-sec/2019/q4/129
https://www.vmware.com/security/advisories/VMSA-2019-0022.html
Lifting embargo.
---
External References:
https://www.vmware.com/security/advisories/VMSA-2019-0022.html
---
The `result` buffer in function ProcessSrvRqst() in file slpd/slpd_process.c is reallocated after computing the expected `size`. However, the size is computed using the `urllen` fields from each SLPUrlEntry, while the memcpy in that
http://www.openwall.com/lists/oss-security/2019/12/10/2http://www.openwall.com/lists/oss-security/2019/12/11/2http://www.vmware.com/security/advisories/VMSA-2019-0022.htmlhttps://access.redhat.com/errata/RHSA-2019:4240https://access.redhat.com/errata/RHSA-2020:0199https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DA3LYAJ2NRKMOZLZOQNDJ5TNQRFMWGHF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZPXXJZLPLAQULBCJVI5NNWZ3PGWXGXWG/https://security.gentoo.org/glsa/202005-12http://www.openwall.com/lists/oss-security/2019/12/10/2http://www.openwall.com/lists/oss-security/2019/12/11/2http://www.vmware.com/security/advisories/VMSA-2019-0022.htmlhttps://access.redhat.com/errata/RHSA-2019:4240https://access.redhat.com/errata/RHSA-2020:0199https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DA3LYAJ2NRKMOZLZOQNDJ5TNQRFMWGHF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZPXXJZLPLAQULBCJVI5NNWZ3PGWXGXWG/https://security.gentoo.org/glsa/202005-12https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-5544
2019-12-06
Published
2021-11-03
Added to CISA KEV
Exploited in the wild