Tuesday, June 3, 2008

Vulnerabilities In VMWare Software

There's been found two vulnerabilities in VMWare software. Both make it possible to execute attacker's code on workstation. First one is in folder handling and the other one in VMCI (Virtual Machine Communication Interface) functionality.

Vulnerable software:
- VMware Workstation 6.0.3 and earlier versions
- VMware Player 2.0.3 and earlier versions
- VMware ACE 2.0.3 and earlier versions
- VMware Fusion 1.1.1 and earlier versions

VMware has released new versions which can be downloaded from the links below:
- VMware Workstation 6.0.4
- VMware Player 2.0.4
- VMware ACE 2.0.4
- VMware Fusion 1.1.3


More information regarding found two vulnerabilities and their fixes can be read here.

1 comment:

certifiedbug said...

Thank you for the heads up Blade.

319.0 MB. ;-)