Geeks for your information
VMware Patches Flaws Disclosed at Pwn2Own 2019 - Printable Version

+- Geeks for your information (https://www.geeks.fyi)
+-- Forum: News (https://www.geeks.fyi/forumdisplay.php?fid=105)
+--- Forum: Software & Services News (https://www.geeks.fyi/forumdisplay.php?fid=145)
+--- Thread: VMware Patches Flaws Disclosed at Pwn2Own 2019 (/showthread.php?tid=6428)



VMware Patches Flaws Disclosed at Pwn2Own 2019 - silversurfer - 30 March 19

Quote:Security updates released on Thursday by VMware for its vCloud Director, ESXi, Workstation and Fusion products patch several vulnerabilities, including ones disclosed recently at the Pwn2Own 2019 hacking competition.
 
At Pwn2Own 2019, Amat Cama and Richard Zhu of team Fluoroacetate demonstrated two VMware Workstation vulnerabilities, including one that was leveraged in a complex exploit targeting Microsoft’s Edge browser. They earned $70,000 for escaping a VMware Workstation virtual machine and executing code on the underlying host operating system, and $130,000 for the Edge exploit.
 
Updates released by VMware this week for ESXi, Workstation, and Fusion (only on macOS) address these flaws. The vendor has described the issues as an out-of-bounds read/write vulnerability and a Time-of-Check-Time-of-Use (TOCTOU) bug in the virtual USB 1.1 Universal Host Controller Interface (UHCI). The CVE identifiers CVE-2019-5518 and CVE-2019-5519 have been assigned to these vulnerabilities, with both classified as “critical.”

SOURCE: https://www.securityweek.com/vmware-patches-flaws-disclosed-pwn2own-2019


RE: VMware Patches Flaws Disclosed at Pwn2Own 2019 - Deep900 - 31 March 19

It's good that those vulnerabilities have been fixed, escaping from the VM and affect also the real machine is a critical security aspect for virtual machines.