CVE-2019-5544

Vulnerability updated 4 months ago (2024-05-04T17:41:08.710Z)
Download STIX
Preview STIX
CVE-2019-5544 is a significant vulnerability involving a flaw in the software design or implementation of VMWare's OpenSLP service. This vulnerability, known as a heap buffer overflow, can potentially allow an attacker to execute arbitrary code on the server and compromise the system. OpenSLP (Service Location Protocol) is an open-source implementation of the Service Location Protocol, which provides a framework to allow networking applications to discover the existence, location, and configuration of networked services in enterprise networks. A few months ago, Juniper discovered a custom Python backdoor that specifically targeted VMWare ESXi servers by exploiting this vulnerability. The discovery underscored the severity and potential misuse of CVE-2019-5544. This backdoor allowed unauthorized users to gain access and control over the affected servers, posing serious security threats to organizations using VMWare ESXi servers. To mitigate these risks, Check Point IPS has developed protection against this threat. Their Intrusion Prevention System (IPS) is designed to identify and block attempts to exploit this vulnerability, providing a crucial layer of defense for VMWare OpenSLP. This protective measure covers not only CVE-2019-5544 but also other related vulnerabilities such as CVE-2020-3992 and CVE-2021-21974, ensuring comprehensive security coverage for VMWare users.
Description last updated: 2024-05-04T16:52:26.756Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the CVE-2019-5544 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Checkpoint
2 years ago
6th February – Threat Intelligence Report - Check Point Research
CERT-EU
2 years ago
13th February – Threat Intelligence Report - Check Point Research
CERT-EU
2 years ago
Out-of-bounds write in IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products
SANS ISC
a year ago
InfoSec Handlers Diary Blog - SANS Internet Storm Center