Thread Rating:
  • 2 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
VMware Patches Flaws Disclosed at Pwn2Own 2019
#1
Quote:Security updates released on Thursday by VMware for its vCloud Director, ESXi, Workstation and Fusion products patch several vulnerabilities, including ones disclosed recently at the Pwn2Own 2019 hacking competition.
 
At Pwn2Own 2019, Amat Cama and Richard Zhu of team Fluoroacetate demonstrated two VMware Workstation vulnerabilities, including one that was leveraged in a complex exploit targeting Microsoft’s Edge browser. They earned $70,000 for escaping a VMware Workstation virtual machine and executing code on the underlying host operating system, and $130,000 for the Edge exploit.
 
Updates released by VMware this week for ESXi, Workstation, and Fusion (only on macOS) address these flaws. The vendor has described the issues as an out-of-bounds read/write vulnerability and a Time-of-Check-Time-of-Use (TOCTOU) bug in the virtual USB 1.1 Universal Host Controller Interface (UHCI). The CVE identifiers CVE-2019-5518 and CVE-2019-5519 have been assigned to these vulnerabilities, with both classified as “critical.”

SOURCE: https://www.securityweek.com/vmware-patc...n2own-2019
[-] The following 2 users say Thank You to silversurfer for this post:
  • Deep900, harlan4096
Reply
#2
It's good that those vulnerabilities have been fixed, escaping from the VM and affect also the real machine is a critical security aspect for virtual machines.
[-] The following 2 users say Thank You to Deep900 for this post:
  • harlan4096, silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AOMEI BackUpper 7.3.4
Version 7.3.4 (Mar...harlan4096 — 10:35
FastCopy 5.7.3
FastCopy 5.7.3: ...harlan4096 — 10:32
Antivirus Removal Tool 2024.03 (v.1)
Antivirus Removal ...harlan4096 — 06:49
Microsoft shows another Bing popup adver...
Microsoft has done...harlan4096 — 06:47
Free Download Manager 6.21.0.5629
Changes in 6.21.0.5...harlan4096 — 08:01

[-]
Birthdays
Today's Birthdays
avatar (41)Hectorvot
avatar (49)knowhanPluts
avatar (37)Williamengiz
Upcoming Birthdays
avatar (42)gapedDow
avatar (36)snorydar
avatar (44)qaqapeti
avatar (42)battsourIonix
avatar (41)CedricSek
avatar (36)Charlesfibre
avatar (41)artmaGoork

[-]
Online Staff
There are no staff members currently online.

>