← Back to browse · API

CVE-2019-5544

Severity
CRITICAL
CVSS
9.8
EPSS
0.96823
Risk score
58.89
CISA KEV
Yes
PoC
No
Published
2019-12-06
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2019-15119, GHSA-4734-5452-R5FH
Products
VMware:VMware ESXi and Horizon DaaS, n/a:ESXi and Horizon DaaS ESXi 6.7 prior to patch release ESXi670-201912001, ESXi 6.5 prior to patch release ESXi650-201912001, ESXi 6.0 prior to patch release ESXi600-201912001 and Horizon DaaS 8.x prior to BZ-2467224-Disable_SLPD_service_permanently_801_Hotfix.
Sources
cisa.gov CVE-2019-5544
euvd EUVD-2019-15119

Description

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

References