VMware plugs critical hypervisor holes

By
Follow google news

Affects ESXI, Workstation and Fusion products.

Virtualisation software vendor VMwware has issued patches for a range of vulnerabilities in three of its key products that allow malicious guests to run arbitrary code on their hosts.

VMware plugs critical hypervisor holes

In its security advisory, VMware said the patches fix critical flaws in its ESXI hypervisor product, versions 5.5, 6.0 U1, U2 and U3, and 6.5. Its Fusion 8.x and Workstation 12.x virtual machines have also received patches for critical vulnerabilities.

One flaw takes advantage of a memory corruption bug in the SVGA video subsystem in ESXI, Workstation and Fusion products that allows attackers to execute code on hosts via guests, VMWare said.

The extensible host controller interface (XHCI) that handles USB devices in the above products contains a bug that leads to uninitialised memory usage. 

Again, this flaw can be exploited to allow guests to escape and run code on VMware hosts.

However, the vulnerability can only be used for denial of service attacks on the older ESXI 5.5 hypervisor.

VMware also issued patches for an information leak issue in ESXI, Workstation and Fusion, caused by uninitialised memory usage in the three products.

The company rated the information leak bug severity as moderate.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

CBA builds two AI agents to boost cyber defences

CBA builds two AI agents to boost cyber defences

Researchers uncover 'Darksword' iPhone spyware

Researchers uncover 'Darksword' iPhone spyware

Stryker contains cyber attack on its Microsoft environment

Stryker contains cyber attack on its Microsoft environment

Exploited Google Chrome zero-days added to US must-patch list

Exploited Google Chrome zero-days added to US must-patch list

Log In

  |  Forgot your password?