
By Jim Carr
Excerpt:
“Meanwhile, engineers at Core Security on Friday issued an advisory disclosing a vulnerability that could severely impact organizations that use VMware's desktop virtualization software, VMware Player, Workstation and ACE. They also released a proof-of-concept exploit for the vulnerability to allow testing and assessing the consequences of an attack on the VMware products …
“The vulnerability could grant an attacker complete access to a host system, giving the attacker the ability to create or modify executable files on the host operating system, Ivan Arce, Core Security's CTO, told SCMagazineUS.com. That could allow the attacker to take control of the ‘entire system, including the operating system files,’ he said.”
Source: SC Magazine











