vulnerable software: VMware Workstation 6.0 for Windows, possible some other VMware products as well type of vulnerability: DoS, potential privilege escalation I found a vulnerability in VMware Workstation 6.0 which allows an unprivileged user in the host OS to crash the system and potentially run arbitrary code with kernel privileges. The issue is in the vmstor-60 driver, which is supposed to mount VMware images within the host OS. When sending the IOCTL code FsSetVoleInformation with subcode FsSetFileInformation with a large buffer and underreporting its size to at max 1024 bytes, it will underrun and potentially execute arbitrary code. Security focus
I'm a bit confused as to where VM ends and Brian begins. Am I right in thinking he's not virtual?
ReplyDeleteHearty congratulations - DaPi.
David,
ReplyDeleteIndeed, he's all flesh and blood.
It's just that the long awaited ESX 3.x beta invitations too got sent out on the same date ;-)
Thanks again.
Tarry
Tarry --
ReplyDeleteCongratulations! Start him virtualizing early! :-)
John
Hey John,
ReplyDeleteThanks a lot!
We're looking at the future CEO VMware here..heh heh
I can't believe I missed this post. Congratulations papa! Hope everyone is fine.
ReplyDeleteAll the best,
Bill
That's OK Bill,
ReplyDeleteThanks a lot! :-) Everyone is doing fine indeed.
congratulations... Tarry.
ReplyDeleteI was just browsing your blog & found this post.
Nice blog. Keep on posting...
Thanks pran,
ReplyDeleteAppreciate your kind words.