Skip to content
COOEY

EXPOSURES › CVE-2019-5544

CVE-2019-5544

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-5544 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

VMware ESXi and Horizon DaaS products contained a heap-based buffer overflow vulnerability actively exploited by attackers to achieve remote code execution (RCE).

A buffer overflow in VMware's ESXi and Horizon DaaS products allowed attackers with network access to execute arbitrary code, demonstrating a critical failure in secure coding practices. DIB organizations using these products face significant exposure to ransomware and other malicious attacks, potentially impacting CMMC compliance and requiring immediate mitigation. Patching and hardening network configurations are essential.

Shame score — VMware's history of critical RCE vulnerabilities in core products, coupled with active exploitation by ransomware, highlights a pattern of negligence and inadequate security controls.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized