VMware
Attackers exploiting a VMware flaw would have the ability to run code

VMware issues 'critical' security alert

Major problem with shared folders

Written by Shaun Nichols in California

Security professionals make extensive use of virtualisation technologies for malware analysis

Raul Siles Researcher, Sans Institute

VMware has warned of a 'critical' vulnerability in several of the company's virtualisation products.

The issue exists in a shared folders feature which allows guest access to files.

An advisory released by the company warned that an attacker with access to a guest folder could exploit the vulnerability to gain complete access to the machine running VMware.

The attacker would also have the ability to run code, allowing for the remote installation and execution of malware.

The vulnerability affects the Windows versions of VMware Workstation 6.0.2 and earlier versions, Player 2.0.2 and earlier and ACE 2.0.2 and earlier. VMWare Server, ESX Server or any Mac or Linux VMWare products are not affected.

The company credited security firm Core Security Technologies with discovering the flaw.

Sans researcher Raul Siles pointed out that the flaw could pose the greatest danger to the very people who fight malware.

"The impact on production environments is supposed to be limited as they tend to use the server versions," Siles wrote on a company blog.

"However, as security professionals, we make extensive use of virtualisation technologies for malware analysis, incident response, forensics, security testing, training etc, and we typically use the client versions of the products. "

There is no fix for the flaw currently available. VMware urged users to protect against the attack by disabling the shared folders feature.

VMware Security Alert: Critical VMware Security Alert for Windows-Hosted VMware Workstation, VMware Player, and VMware ACE

Tags:

Further reading

Cyber-squatters reaping rich rewards

But brand holders are fighting back   More...

Microsoft posts Vista SP1 blacklist

Redmond names incompatible applications   More...

VMware discusses the state of virtualization

VMWare chief executive Diane Greene and AMD CEO Hector Ruiz discuss the state of virtualization   More...

VMware Fusion 1.1.2

Windows XP or Vista on your Intel Mac   More...

Related articles

Adobe issues critical fix

Holes patched in Reader and Acrobat   More...

IM flaw hits millions of AOL users

Users exposed to immediate high-risk attacks, warns security firm   More...

Microsoft delivers four security fixes

Three 'critical' one 'moderate'   More...

Web attacks target PDF flaw

Users urged to patch Acrobat hole   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement