9.8

CVE-2019-5544

Warnung

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMwareHorizon Daas Version >= 8.0.0 < 9.0.0.0
VMwareESXi Version6.0 Update-
VMwareESXi Version6.0 Update1
VMwareESXi Version6.0 Update1a
VMwareESXi Version6.0 Update1b
VMwareESXi Version6.0 Update2
VMwareESXi Version6.0 Update3
VMwareESXi Version6.0 Update3a
VMwareESXi Version6.0 Update600-201504401
VMwareESXi Version6.0 Update600-201505401
VMwareESXi Version6.0 Update600-201507101
VMwareESXi Version6.0 Update600-201507102
VMwareESXi Version6.0 Update600-201507401
VMwareESXi Version6.0 Update600-201507402
VMwareESXi Version6.0 Update600-201507403
VMwareESXi Version6.0 Update600-201507404
VMwareESXi Version6.0 Update600-201507405
VMwareESXi Version6.0 Update600-201507406
VMwareESXi Version6.0 Update600-201507407
VMwareESXi Version6.0 Update600-201509101
VMwareESXi Version6.0 Update600-201509102
VMwareESXi Version6.0 Update600-201509201
VMwareESXi Version6.0 Update600-201509202
VMwareESXi Version6.0 Update600-201509203
VMwareESXi Version6.0 Update600-201509204
VMwareESXi Version6.0 Update600-201509205
VMwareESXi Version6.0 Update600-201509206
VMwareESXi Version6.0 Update600-201509207
VMwareESXi Version6.0 Update600-201509208
VMwareESXi Version6.0 Update600-201509209
VMwareESXi Version6.0 Update600-201509210
VMwareESXi Version6.0 Update600-201510401
VMwareESXi Version6.0 Update600-201511401
VMwareESXi Version6.0 Update600-201601101
VMwareESXi Version6.0 Update600-201601102
VMwareESXi Version6.0 Update600-201601401
VMwareESXi Version6.0 Update600-201601402
VMwareESXi Version6.0 Update600-201601403
VMwareESXi Version6.0 Update600-201601404
VMwareESXi Version6.0 Update600-201601405
VMwareESXi Version6.0 Update600-201602401
VMwareESXi Version6.0 Update600-201603101
VMwareESXi Version6.0 Update600-201603102
VMwareESXi Version6.0 Update600-201603201
VMwareESXi Version6.0 Update600-201603202
VMwareESXi Version6.0 Update600-201603203
VMwareESXi Version6.0 Update600-201603204
VMwareESXi Version6.0 Update600-201603205
VMwareESXi Version6.0 Update600-201603206
VMwareESXi Version6.0 Update600-201603207
VMwareESXi Version6.0 Update600-201603208
VMwareESXi Version6.0 Update600-201605401
VMwareESXi Version6.0 Update600-201608101
VMwareESXi Version6.0 Update600-201608401
VMwareESXi Version6.0 Update600-201608402
VMwareESXi Version6.0 Update600-201608403
VMwareESXi Version6.0 Update600-201608404
VMwareESXi Version6.0 Update600-201608405
VMwareESXi Version6.0 Update600-201610410
VMwareESXi Version6.0 Update600-201611401
VMwareESXi Version6.0 Update600-201611402
VMwareESXi Version6.0 Update600-201611403
VMwareESXi Version6.0 Update600-201702101
VMwareESXi Version6.0 Update600-201702102
VMwareESXi Version6.0 Update600-201702201
VMwareESXi Version6.0 Update600-201702202
VMwareESXi Version6.0 Update600-201702203
VMwareESXi Version6.0 Update600-201702204
VMwareESXi Version6.0 Update600-201702205
VMwareESXi Version6.0 Update600-201702206
VMwareESXi Version6.0 Update600-201702207
VMwareESXi Version6.0 Update600-201702208
VMwareESXi Version6.0 Update600-201702209
VMwareESXi Version6.0 Update600-201702210
VMwareESXi Version6.0 Update600-201702211
VMwareESXi Version6.0 Update600-201702212
VMwareESXi Version6.0 Update600-201703401
VMwareESXi Version6.0 Update600-201706101
VMwareESXi Version6.0 Update600-201706102
VMwareESXi Version6.0 Update600-201706103
VMwareESXi Version6.0 Update600-201706401
VMwareESXi Version6.0 Update600-201706402
VMwareESXi Version6.0 Update600-201706403
VMwareESXi Version6.0 Update600-201710301
VMwareESXi Version6.0 Update600-201811001
VMwareESXi Version6.0 Update600-201811401
VMwareESXi Version6.5 Update-
VMwareESXi Version6.5 Update650-201701001
VMwareESXi Version6.5 Update650-201703001
VMwareESXi Version6.5 Update650-201703002
VMwareESXi Version6.5 Update650-201704001
VMwareESXi Version6.5 Update650-201707101
VMwareESXi Version6.5 Update650-201707102
VMwareESXi Version6.5 Update650-201707103
VMwareESXi Version6.5 Update650-201707201
VMwareESXi Version6.5 Update650-201707202
VMwareESXi Version6.5 Update650-201707203
VMwareESXi Version6.5 Update650-201707204
VMwareESXi Version6.5 Update650-201707205
VMwareESXi Version6.5 Update650-201707206
VMwareESXi Version6.5 Update650-201707207
VMwareESXi Version6.5 Update650-201707208
VMwareESXi Version6.5 Update650-201707209
VMwareESXi Version6.5 Update650-201707210
VMwareESXi Version6.5 Update650-201707211
VMwareESXi Version6.5 Update650-201707212
VMwareESXi Version6.5 Update650-201707213
VMwareESXi Version6.5 Update650-201707214
VMwareESXi Version6.5 Update650-201707215
VMwareESXi Version6.5 Update650-201707216
VMwareESXi Version6.5 Update650-201707217
VMwareESXi Version6.5 Update650-201707218
VMwareESXi Version6.5 Update650-201707219
VMwareESXi Version6.5 Update650-201707220
VMwareESXi Version6.5 Update650-201707221
VMwareESXi Version6.5 Update650-201710001
VMwareESXi Version6.5 Update650-201712001
VMwareESXi Version6.5 Update650-201803001
VMwareESXi Version6.5 Update650-201806001
VMwareESXi Version6.5 Update650-201808001
VMwareESXi Version6.5 Update650-201810001
VMwareESXi Version6.5 Update650-201810002
VMwareESXi Version6.5 Update650-201811001
VMwareESXi Version6.5 Update650-201811002
VMwareESXi Version6.5 Update650-201811301
VMwareESXi Version6.5 Update650-201901001
VMwareESXi Version6.5 Update650-201903001
VMwareESXi Version6.5 Update650-201905001
VMwareESXi Version6.5 Update650-201908001
VMwareESXi Version6.5 Update650-201910001
VMwareESXi Version6.5 Update650-20191004001
VMwareESXi Version6.5 Update650-201911001
VMwareESXi Version6.5 Update650-201911401
VMwareESXi Version6.5 Update650-201911402
VMwareESXi Version6.7 Update-
VMwareESXi Version6.7 Update670-201806001
VMwareESXi Version6.7 Update670-201807001
VMwareESXi Version6.7 Update670-201808001
VMwareESXi Version6.7 Update670-201810001
VMwareESXi Version6.7 Update670-201810101
VMwareESXi Version6.7 Update670-201810102
VMwareESXi Version6.7 Update670-201810103
VMwareESXi Version6.7 Update670-201810201
VMwareESXi Version6.7 Update670-201810202
VMwareESXi Version6.7 Update670-201810203
VMwareESXi Version6.7 Update670-201810204
VMwareESXi Version6.7 Update670-201810205
VMwareESXi Version6.7 Update670-201810206
VMwareESXi Version6.7 Update670-201810207
VMwareESXi Version6.7 Update670-201810208
VMwareESXi Version6.7 Update670-201810209
VMwareESXi Version6.7 Update670-201810210
VMwareESXi Version6.7 Update670-201810211
VMwareESXi Version6.7 Update670-201810212
VMwareESXi Version6.7 Update670-201810213
VMwareESXi Version6.7 Update670-201810214
VMwareESXi Version6.7 Update670-201810215
VMwareESXi Version6.7 Update670-201810216
VMwareESXi Version6.7 Update670-201810217
VMwareESXi Version6.7 Update670-201810218
VMwareESXi Version6.7 Update670-201810219
VMwareESXi Version6.7 Update670-201810220
VMwareESXi Version6.7 Update670-201810221
VMwareESXi Version6.7 Update670-201810222
VMwareESXi Version6.7 Update670-201810223
VMwareESXi Version6.7 Update670-201810224
VMwareESXi Version6.7 Update670-201810225
VMwareESXi Version6.7 Update670-201810226
VMwareESXi Version6.7 Update670-201810227
VMwareESXi Version6.7 Update670-201810228
VMwareESXi Version6.7 Update670-201810229
VMwareESXi Version6.7 Update670-201810230
VMwareESXi Version6.7 Update670-201810231
VMwareESXi Version6.7 Update670-201810232
VMwareESXi Version6.7 Update670-201810233
VMwareESXi Version6.7 Update670-201810234
VMwareESXi Version6.7 Update670-201811001
VMwareESXi Version6.7 Update670-201901001
VMwareESXi Version6.7 Update670-201901401
VMwareESXi Version6.7 Update670-201901402
VMwareESXi Version6.7 Update670-201901403
VMwareESXi Version6.7 Update670-201903001
VMwareESXi Version6.7 Update670-201904001
VMwareESXi Version6.7 Update670-201904201
VMwareESXi Version6.7 Update670-201904202
VMwareESXi Version6.7 Update670-201904203
VMwareESXi Version6.7 Update670-201904204
VMwareESXi Version6.7 Update670-201904205
VMwareESXi Version6.7 Update670-201904206
VMwareESXi Version6.7 Update670-201904207
VMwareESXi Version6.7 Update670-201904208
VMwareESXi Version6.7 Update670-201904209
VMwareESXi Version6.7 Update670-201904210
VMwareESXi Version6.7 Update670-201904211
VMwareESXi Version6.7 Update670-201904212
VMwareESXi Version6.7 Update670-201904213
VMwareESXi Version6.7 Update670-201904214
VMwareESXi Version6.7 Update670-201904215
VMwareESXi Version6.7 Update670-201904216
VMwareESXi Version6.7 Update670-201904217
VMwareESXi Version6.7 Update670-201904218
VMwareESXi Version6.7 Update670-201904219
VMwareESXi Version6.7 Update670-201904220
VMwareESXi Version6.7 Update670-201904221
VMwareESXi Version6.7 Update670-201904222
VMwareESXi Version6.7 Update670-201904223
VMwareESXi Version6.7 Update670-201904224
VMwareESXi Version6.7 Update670-201904225
VMwareESXi Version6.7 Update670-201904226
VMwareESXi Version6.7 Update670-201904227
VMwareESXi Version6.7 Update670-201904228
VMwareESXi Version6.7 Update670-201904229
VMwareESXi Version6.7 Update670-201905001
VMwareESXi Version6.7 Update670-201906002
VMwareESXi Version6.7 Update670-201908101
VMwareESXi Version6.7 Update670-201908102
VMwareESXi Version6.7 Update670-201908103
VMwareESXi Version6.7 Update670-201908104
VMwareESXi Version6.7 Update670-201908201
VMwareESXi Version6.7 Update670-201908202
VMwareESXi Version6.7 Update670-201908203
VMwareESXi Version6.7 Update670-201908204
VMwareESXi Version6.7 Update670-201908205
VMwareESXi Version6.7 Update670-201908206
VMwareESXi Version6.7 Update670-201908207
VMwareESXi Version6.7 Update670-201908208
VMwareESXi Version6.7 Update670-201908209
VMwareESXi Version6.7 Update670-201908210
VMwareESXi Version6.7 Update670-201908211
VMwareESXi Version6.7 Update670-201908212
VMwareESXi Version6.7 Update670-201908213
VMwareESXi Version6.7 Update670-201908214
VMwareESXi Version6.7 Update670-201908215
VMwareESXi Version6.7 Update670-201908216
VMwareESXi Version6.7 Update670-201908217
VMwareESXi Version6.7 Update670-201908218
VMwareESXi Version6.7 Update670-201908219
VMwareESXi Version6.7 Update670-201908220
VMwareESXi Version6.7 Update670-201908221
VMwareESXi Version6.7 Update670-201911001
OpenslpOpenslp Version <= 2.0.0
FedoraprojectFedora Version30
FedoraprojectFedora Version31

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability

Schwachstelle

VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 93.04% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.