CVE-2019-5544 is a critical remote code execution vulnerability in OpenSLP as used by VMware ESXi and VMware Horizon DaaS appliances. The flaw is described as a heap overwrite during processing of SLP messages, allowing memory corruption in the OpenSLP service. Publicly cited sources characterize the issue as reachable over the network without authentication or user interaction, with exploitation occurring via access to the SLP service on port 427. VMware advisory VMSA-2019-0022 identifies affected ESXi 6.0, 6.5, and 6.7 builds prior to the December 2019 patch releases, as well as Horizon DaaS 8.x prior to the vendor hotfix/upgrade path.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains two Python proof-of-concept (PoC) exploits targeting VMware ESXi's OpenSLP service vulnerabilities: CVE-2019-5544 and CVE-2020-3992. The structure is simple, with two main Python scripts (CVE_2019_5544.py and CVE_2020_3992.py) and a README.md. Each script constructs custom SLP protocol packets and sends them over TCP to port 427 of a specified target IP address (default: 192.168.110.129). The payloads are designed to trigger heap overflows or other memory corruption issues in the OpenSLP service, as described in the respective CVEs. The README provides brief usage notes and mentions that the PoCs were tested on ESXi installed in VMware Workstation. The scripts do not provide post-exploitation capabilities such as shell access; they are intended to demonstrate the vulnerabilities' existence and potential for service disruption. The repository is suitable for researchers or administrators seeking to test for these specific vulnerabilities in their ESXi environments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A heap overflow vulnerability in OpenSLP where a crafted payload can crash the service; the content discusses improving detection logic to avoid false positives by first confirming OpenSLP is running on port 427.
A critical remote code execution vulnerability involving a heap overwrite issue in OpenSLP as used by VMware ESXi and Horizon DaaS appliances.
A critical unauthenticated remote code execution vulnerability affecting VMware ESXi/OpenSLP, enabling remote attackers to execute arbitrary code via crafted SLP messages.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.