VMware Patches Flaws Disclosed at Pwn2Own 2019
#1
Quote:Security updates released on Thursday by VMware for its vCloud Director, ESXi, Workstation and Fusion products patch several vulnerabilities, including ones disclosed recently at the Pwn2Own 2019 hacking competition.
 
At Pwn2Own 2019, Amat Cama and Richard Zhu of team Fluoroacetate demonstrated two VMware Workstation vulnerabilities, including one that was leveraged in a complex exploit targeting Microsoft’s Edge browser. They earned $70,000 for escaping a VMware Workstation virtual machine and executing code on the underlying host operating system, and $130,000 for the Edge exploit.
 
Updates released by VMware this week for ESXi, Workstation, and Fusion (only on macOS) address these flaws. The vendor has described the issues as an out-of-bounds read/write vulnerability and a Time-of-Check-Time-of-Use (TOCTOU) bug in the virtual USB 1.1 Universal Host Controller Interface (UHCI). The CVE identifiers CVE-2019-5518 and CVE-2019-5519 have been assigned to these vulnerabilities, with both classified as “critical.”

SOURCE: https://www.securityweek.com/vmware-patc...n2own-2019
[-] The following 2 users say Thank You to silversurfer for this post:
  • Deep900, harlan4096
Reply
#2
It's good that those vulnerabilities have been fixed, escaping from the VM and affect also the real machine is a critical security aspect for virtual machines.
[-] The following 2 users say Thank You to Deep900 for this post:
  • harlan4096, silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Microsoft Defender Antivirus security in...
September-2025 (Pl...harlan4096 — 09:38
UltraSearch 4.8.4
Version 4.8.4 1...harlan4096 — 09:35
Brave 1.83.120
Release Channel 1....harlan4096 — 09:34
Meta launches new anti-scam tools for Wh...
Meta has announced...harlan4096 — 09:33
YouTube is adding an option to limit the...
YouTube is rolling...harlan4096 — 09:28

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (47)Michaelaceve
avatar (37)QuadirLigh
avatar (38)Mblippek
avatar (44)viecontAceve

[-]
Online Staff
Decimuss's profile Decimuss

>