I just did a NDA session with Citrix and was told of some really cool stuff that Citrix will be announcing. Obviously I am not at a liberty to reveal it yet but you can already start guessing. As a hint, you know where my focus is right now ;-)
vulnerable software: VMware Workstation 6.0 for Windows, possible some other VMware products as well type of vulnerability: DoS, potential privilege escalation I found a vulnerability in VMware Workstation 6.0 which allows an unprivileged user in the host OS to crash the system and potentially run arbitrary code with kernel privileges. The issue is in the vmstor-60 driver, which is supposed to mount VMware images within the host OS. When sending the IOCTL code FsSetVoleInformation with subcode FsSetFileInformation with a large buffer and underreporting its size to at max 1024 bytes, it will underrun and potentially execute arbitrary code. Security focus
Hey, I dont get it! Give-me another hint please!!!
ReplyDeleteWhat is it with all this NDA stuff? Check out http://channelvirtualization.wordpress.com/2008/09/08/xenserver-50-out-on-sept-15th/
ReplyDeleteThere is even an article on http://techworld.nl/article/5646/citrix-tilt-xenserver-naar-versie-5punt0.html
Regards
Citrix Workflow Studio RTM?
ReplyDeleteXenserver 5.0
ReplyDeleteVery good. Still the most exciting part is still missing :-)
ReplyDeleteThis link suggest Microsoft is buying Citrix!
ReplyDeletehttp://www.dabcc.com/article.aspx?id=8564