cbcvebase.
CVE-2019-5544
published 2019-12-06

CVE-2019-5544: OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical…

PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
96.82%
99.9th percentile
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
fedoraprojectfedora
fedoraprojectfedora
msrcazl3_openslp_2.0.0-26_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_openslp_2.0.0-26_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
openslpopenslp<= 2.0.0
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_power_big_endian
redhatenterprise_linux_for_power_big_endian
redhatenterprise_linux_for_power_big_endian_eus
redhatenterprise_linux_for_power_little_endian
redhatenterprise_linux_for_power_little_endian_eus
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation

Detection & IOCsextracted from sources · hover to see the quote

port427
hash12ee27f56ec8a2a3eb2fe69179be3f7a7193ce2b92963ad33356ed299f7ed975
hash17139a10fd226d01738fe9323918614aa913b2a50e1a516e95cced93fa151c61
hash43e61519be440115eeaa3738a0e4aa4bb3c8ac5f9bdfce1a896db17a374eb8aa
hashafb22b1ff281c085b60052831ead0a0ed300fac0160f87851dacc67d4e158178
hashf764c49daffdacafa94aaece1d5094e0fac794639758e673440329b02c0fda39
ip45.112.240.81
ip77.243.181.196
  • Monitor for inbound TCP connections to port 427 on ESXi hosts and Horizon DaaS appliances, especially from unexpected or external sources, as this is the attack vector for CVE-2019-5544 OpenSLP heap overwrite exploitation.
  • Hunt for ESXiArgs ransomware compromise by querying for HTTP responses containing the ransom note title 'How to Restore Your Files' on public-facing ESXi host IPs (Censys query: services.http.response.body: "How to Restore Your Files" and services.http.response.html_title:"How to Restore Your Files").
  • Check Point IPS signature 'VMWare OpenSLP Heap Buffer Overflow (CVE-2019-5544; CVE-2021-21974)' provides detection coverage for exploitation attempts against this vulnerability.
  • ·The ESXiArgs ransomware campaign's initial access CVE has not been definitively confirmed by first-party sources; CVE-2021-21974 is widely cited but VMware stated no 0-day was used, and CVE-2019-5544 / CVE-2020-3992 remain plausible alternative vectors.
  • ·The DarkSide ransomware SHA-256 hashes listed are associated with DarkSide payloads that exploited CVE-2019-5544 as part of their VMware ESXi attack chain, not the CVE exploit itself.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.