Telecom Tidbits
Jared's Network and Security Blog
  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links

VMware Exploited Again: Update Now

September 22, 2017 Jared Hall General, Internet Security

On Friday, 9/15/2017, VMware released patches for the ESXi Server, Workstation, and Fusion (Apple) hypervisors.  The most serious issue, an out-of-bounds write vulnerability, exists in ESXi, and desktop hypervisors Workstation, and Fusion. An attacker could exploit the issue, which exists in a SVGA device, to execute code on the host O/S.  This affects ESXi version 6.5, Workstation version 12.X, and Fusion 8.X.

This is a serious problem; one of the reasons that privacy advocates do not put stuff on public Cloud Servers.  As stated many times before; do not put stuff in the public Cloud that you can’t afford to be lost or exploited.

Another bug was fixed in VMware’s vCenter Server, used in vSphere environments.  This bug fixes a XSS (Cross-Site Scripting) vulnerability in the HTML5 client.  This bug exists in version 6.5 of vCenter Server and users should update to version 6.5 U1.

The VMware Security Advisory can be found here.

 

 

« WordPress 4.8.2: Update Now. » Microsoft Office: No Shortage of Exploits

Tools & Downloads

Download Center

Categories

Good Reads (PDF)

Recent Posts

  • PayPal Woes and Degenerative AI
  • A Pathetic Defense of Julian Assange
  • Damned if you do. Damned if you don’t.
  • ProtonMail? Not Worth an Electron!
  • Give it a REST: Serious WordPress Bugs
$
Select Payment Method
Personal Info

Donation Total: $20.00

↑

  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links
Temporal Based Intelligence © 2017