CVE-2019-5544: VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 97.3% chance of exploitation in the next 30 days.

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

Affected products

  • Fedoraproject Fedora: version 30 only; version 31 only
  • Openslp Openslp: up to and including 2.0.0
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 6.0_s390x only; version 7.0_s390x only
  • Red Hat Enterprise Linux For IBM Z Systems Eus: version 7.7_s390x only
  • Red Hat Enterprise Linux For Power Big Endian: version 6.0_ppc64 only; version 7.0_ppc64 only
  • Red Hat Enterprise Linux For Power Big Endian Eus: version 7.7_ppc64 only
  • Red Hat Enterprise Linux For Power Little Endian: version 7.0_ppc64le only
  • Red Hat Enterprise Linux For Power Little Endian Eus: version 7.7_ppc64le only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.7 only
  • Red Hat Enterprise Linux Server Eus: version 7.7 only
  • Red Hat Enterprise Linux Server Tus: version 7.7 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
  • VMware ESXi: version 6.0 only; version 6.5 only; version 6.7 only
  • VMware Horizon DaaS: from 8.0.0, before 9.0.0.0 (fixed in 9.0.0.0)

Published 2019-12-06. Last modified 2026-06-17.