PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-5544 VMware CVE debrief

CVE-2019-5544 is a VMware OpenSLP heap-based buffer overflow affecting VMware ESXi and Horizon DaaS. CISA has listed it in the Known Exploited Vulnerabilities catalog, and the KEV entry indicates known ransomware campaign use. That combination makes it a high-priority remediation item for any exposed VMware environment.

Vendor
VMware
Product
VMware ESXi and Horizon DaaS
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2021-11-03
Original CVE updated
2021-11-03
Advisory published
2021-11-03
Advisory updated
2021-11-03

Who should care

VMware ESXi and Horizon DaaS administrators, virtualization platform owners, SOC teams monitoring edge-facing services, and incident responders responsible for systems exposed to the network.

Technical summary

The supplied records identify a heap-based buffer overflow in OpenSLP associated with VMware ESXi and Horizon DaaS. The vulnerability is tracked as a CVE and appears in CISA's KEV catalog, which also marks it as having known ransomware campaign use. No CVSS score was provided in the supplied corpus.

Defensive priority

High. CISA KEV inclusion and the noted ransomware campaign use mean this issue should be treated as a top-tier patching and exposure-management item, especially on internet-accessible or broadly reachable VMware deployments.

Recommended defensive actions

  • Apply vendor-provided updates per VMware instructions.
  • Prioritize remediation on any ESXi or Horizon DaaS systems that are reachable from untrusted networks.
  • Verify whether OpenSLP is enabled where it is not required and disable or restrict it according to vendor guidance.
  • Inventory all affected VMware assets and confirm patch status across clusters and pools.
  • Monitor for suspicious activity on exposed VMware management and service endpoints.
  • Use the CISA KEV due date as an operational benchmark for backlog and exception review, even though the current record date is older.

Evidence notes

This debrief is based only on the supplied CVE metadata, CISA KEV metadata, and official resource links. The corpus identifies the issue as 'VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability,' marks it as KEV-listed, and records 'Known' ransomware campaign use. No additional technical detail, exploit behavior, or severity score was supplied.

Sources and references

Verified primary and authoritative sources

  • CVE-2019-5544 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2019-5544

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2019-5544 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2019-5544

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.