Back

CRITICAL KEV Used in ransomware campaigns

openslp: Heap-based buffer overflow in ProcessSrvRqst() in slpd_process.c leading to remote code execution

Published Dec 6, 2019 ·Due May 3, 2022

Description

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of openslp as shipped with Red Hat Enterprise Linux 8 as they did not include the slpd service component.

Red Hat mitigation

There is no known mitigation.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published Dec 6, 2019
Updated Oct 21, 2025
Reserved Jan 7, 2019
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Dec 6, 2019