Wednesday, April 15, 2009

Critical Vulnerability In VMware

There has been found a critical vulnerability in VMware virtualization software products. The vulnerability in the virtual machine display function might allow a guest operating system to run code on the host.

Affected versions are:
-VMware Workstation 6.5.1 and earlier,
-VMware Player 2.5.1 and earlier,
-VMware ACE 2.5.1 and earlier,
-VMware Server 2.0,
-VMware Server 1.0.8 and earlier,
-VMware Fusion 2.0.3 and earlier,
-VMware ESXi 3.5 without patch ESXe350-200904201-O-SG,
-VMware ESX 3.5 without patch ESX350-200904201-SG,
-VMware ESX 3.0.3 without patch ESX303-200904403-SG,
-VMware ESX 3.0.2 without patch ESX-1008421.

Users of affected versions are recommended to update their versions according to the VMware's instructions.

No comments: