VMware patches new critical security vulnerability

By
Follow google news

VMware has issued patches for a critical security vulnerability in its ESX and ESXi virtualisation products.

The issue is new, different from the vulnerability in a guest virtual device driver that was patched by VMware earlier this week. That earlier flaw could cause a potential denial-of-service, and affected Workstation, Player, ACE, Server, ESX and ESXi virtualisation products.

One of the reasons this new vulnerability was labeled "critical" is that it could affect the underlying host operating system in a virtual environment.

“A critical vulnerability in the virtual machine display function might allow a guest operating system to run code on the host,” the VMware advisory said.

The VMware advisory lists a number of VMware versions that are affected, and whether the patches will properly address the vulnerability. But apparently, some users who have older versions may not be helped.

“Depending on your version, your only option may be to upgrade rather than patch,” wrote Steve Hall, handler at the SANS Internet Storm Center, on the organisation's blog.

The typical way to apply patches to ESXi hosts is through the VMware Update Manager, but ESXi hosts can also be updated by downloading a single offline download file, according to VMware.

See original article on scmagazineus.com


Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Australia's critical infrastructure security laws "toothless"

Australia's critical infrastructure security laws "toothless"

CBA builds two AI agents to boost cyber defences

CBA builds two AI agents to boost cyber defences

"CanisterWorm" supply chain malware attacks npm

"CanisterWorm" supply chain malware attacks npm

US regulator bans imports of new foreign-made routers

US regulator bans imports of new foreign-made routers

Log In

  |  Forgot your password?