
By Peter Judge
Excerpt:
“Core has released proof-of-concept exploit software, which it says demonstrates a serious flaw in VMware's desktop virtualisation software that could give hackers control of virtualised systems, and which it claims VMware has been aware of for four months…
“The security vendor is releasing the exploit in the week of the VMworld event in the hope that publicity will force VMware to take action, and to make users aware of the problem and enable them to ‘safely assess the consequences of an actual network intrusion’, and apply a simple workaround to avoid the problem…
“The vulnerability could allow an attacker to create or modify executable files on the host operating system, through weaknesses in VMware's shared folders feature. Hackers can use a specially crafted PathName to access a VMware shared folder, because VMware does not properly validate PathNames, according to Iván Arce, chief technology officer at Core.”
Source: ZD Net











