News

VMware Fixes Vulnerabilities

VMware has issued patches that will eliminate the vulnerabilities found last month, according to an announcement the company posted on some security news mailing lists today.

The vulnerability allowed users of some VMware products to escape virtualized environments and enter the host systems with full privileges.

To patch the hole, the company has updated:

The vulnerability, called a path traversal, involves the manipulation of VMware shared folders that are used to transfer data between the guest virtualized system and the host system. A user in a virtual environment could type in a path name that would provide entry into the host system, with full read and write privileges.

The vulnerability does not affect ESX Server or Linux versions of the VMware software.

The patches cover CVE-2008-0923, CVE-2008-0923, CVE-2008-1361, CVE-2008-1362, CVE-2007-5269, CVE-2006-2940, CVE-2006-2937, CVE-2006-4343, CVE-2006-4339, CVE-2007-5618, CVE-2008-1364, CVE-2008-1363 and CVE-2008-1340, as categorized by the Common Vulnerabilities and Exposures project.

About the Author

Joab Jackson is the chief technology editor of Government Computing News (GCN.com).

Featured

  • Microsoft Secure Score Hits General Availability

    Microsoft on Monday announced the general availability of the Microsoft Secure Score service within the Microsoft 365 Security Center portal.

  • 2020 Microsoft Conference Calendar: For Partners, IT Pros and Developers

    Here's your guide to all the IT training sessions, partner meet-ups and annual Microsoft conferences you won't want to miss. (Now updated with COVID-19-related event changes.)

  • Microsoft Teams Roadmap: Support for 1,000 Meeting Attendees, New Hardware

    Microsoft Teams is poised to receive a raft of new features in the coming months, many of them designed to make remote videoconferences feel more "natural."

  • The 2020 Microsoft Product Roadmap

    From the next major update to Windows 10 to the next generations of .NET and PowerShell, here's what's on tap from Microsoft this year.

RCP Update

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.