Core Security: VMware Has Serious Security Flaw
By Alice Turner
16:01, February 26th 2008
27 votes
Vote this story
Core Security: VMware Has Serious Security Flaw

Core Security Technologies announced yesterday that VMware’s popular desktop virtualization software has a serious security flaw and released an exploit to test systems for vulnerability. Security experts working for CoreLabs, the research arm of Core Security, discovered that an attacker could gain complete access to a host system by exploiting the VMware flaw, allowing the attacker to create or modify executable files on the host operating system.

“What’s most relevant about this vulnerability is it demonstrates how virtual environments can provide an open door to the underlying infrastructures that host them,” said Iván Arce, CTO at Core Security Technologies, in a statement Monday.

“This vulnerability provides an important wake-up call to security-concerned IT practitioners. It is signals that virtualization is not immune to security flaws and that ‘real’ environments aren’t safe simply because they sit behind virtual environments,” Arce added.

Subsequently, VMware, Inc. has released its own statement which confirms the vulnerability. The company's announcement points out that Windows hosted versions of VMware Workstation 6.0.2 and earlier, VMware Workstation 5.5.4 and earlier, VMware Player 2.0.2 and earlier, VMware Player 1.0.4 and earlier, VMware ACE 2.0.2 and earlier and VMware ACE 1.0.2 and earlier are affected by the flaw.

Furthermore, the flaw is only exploitable if you have configured a VMware host-to-guest shared folder. VMware's shared folders are designed for users to transfer data between a virtualized system (Guest) and the non-virtualized Host system running the virtualized one. The bug enables users of a Guest system read and write access to any portion of the Host's file system including the system folder and other security-sensitive files, VMware said.

The company, founded in 1998, makes desktop software which runs atop Microsoft Windows, Linux, and Mac OS X. VMware also offers enterprise-level software, VMware ESX Server (not affected by this flaw), which runs directly on server hardware without requiring an additional underlying operating system.

VMware is working around the clock on a patch, but in the meanwhile it advises users of shared folders to disable them immediately. Here are their instructions:

To disable shared folders in the Global settings:

   1. From the VMware product's menu, choose Edit > Preferences.
   2. In the Workspace tab, under Virtual Machines, deselect the checkbox for Enable all shared folders by default.

To disable shared folders for the individual virtual machine settings:

   1. From the VMware product's menu, choose VM > Settings.
   2. In the Options tab, select Shared Folders and Disable.



© 2007 - 2008 - eFluxMedia
dotclear

Other News in

Is Powerset And The Semantic Search The Right Choice For Microsoft?

Is Powerset And The Semantic Search The Right Choice For Microsoft?

Desperate to reduce the gap between its search engine, Live Search, and omnipresent Google, Microsoft has been searching lately for the best solution. In just two months, Microsoft announced various...

Apple Slashes Prices For 64GB SSD MacBook Air By $500…Trouble In Paradise?

Apple Slashes Prices For 64GB SSD MacBook Air By $500…Trouble In Paradise?

Maybe because of 4th of July, maybe just out of generosity, or maybe because of the 3G iPhone release, Apple decided to make a delightful surprise to its customers by making an overnight cut of...

Toshiba Doesn’t Give In, Might Add Internet Connectivity To DVD Players

Toshiba Doesn’t Give In, Might Add Internet Connectivity To DVD Players

Ever since Toshiba officially surrendered to Sony’s Blu-ray format in February this year, everyone’s been wondering what their next move will be, and if they’ll ever decide to go to the dark side...

Low-Income Americans Don't Want, Don't Need Broadband Internet

Low-Income Americans Don't Want, Don't Need Broadband Internet

The Pew Internet Project looked at how widespread broadband Internet is among Americans today and found out that there is a large portion of those with low-income who favor their existing dialup...

Now, Google Talk On An iPhone (iPod Touch) Near You

Now, Google Talk On An iPhone (iPod Touch) Near You

The owners of Apple’s ultimate gadget, the iPhone, and those who bought an iPod Touch, will be able to communicate with their friends through Google’s IM client, GTalk. In a note posted on...

dotclear
Latest videos in Technology
Microsoft after Gates
Mobile precautions urged
What Yahoo turned down
iPhones get faster, cheaper
Navigating social media

dotclear
Technology You are here: Technology
» Technology   » Gadgets   » Video Games   
E-mail To A Friend Print RSS Text size: Decrease font size Increase font size
dotclear
dotclear
dotclear
Most Popular in Technology
Windows – Gates’ Not-So-Perfect CreationWindows – Gates’ Not-So-Perfect Creation

» read full story
dotclear

Interested In This Topic?

News Alert will keep you informed. Find out more.
dotclear
Photos Gallery
dotclear
Today's Latest News
West Nile Spreads Due to Flooding, Threatens 4th of July CelebrationsWest Nile Spreads Due to Flooding, Threatens 4th of July Celebrations

» read full story
dotclear