VMware VMCI Arbitrary Code Execution Vulnerability
BID:29443
Info
VMware VMCI Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 29443 |
| Class: | Unknown |
| CVE: |
CVE-2008-2099 |
| Remote: | No |
| Local: | Yes |
| Published: | May 30 2008 12:00AM |
| Updated: | Sep 05 2008 06:51PM |
| Credit: | Andrew Honig of the Department of Defense |
| Vulnerable: |
VMWare Workstation 6.0.4 VMWare Workstation 6.0.3 VMWare Workstation 6.0.2 VMWare Workstation 6.0.1 VMWare Workstation 6.0 VMWare Player 2.0.4 VMWare Player 2.0.2 VMWare Player 2.0.1 VMWare Player 2.0 VMWare ACE 2.0.2 VMWare ACE 2.0.1 VMWare ACE 2.0 |
| Not Vulnerable: |
VMWare Workstation 6.0.4 build 93057 VMWare Player 2.0.4 build 93057 VMWare ACE 2.0.2 build 93057 |
Discussion
VMware VMCI Arbitrary Code Execution Vulnerability
Multiple VMware hosted products with VMCI enabled are prone to a vulnerability that lets attackers execute arbitrary code. This issue affects Microsoft Windows-based hosts only.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successfully exploiting this issue can completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition.
This issue affects the following VMware products:
VMware Workstation prior to 6.0.4 build 93057
VMware Player prior to 2.0.4 build 93057
VMware ACE prior to 2.0.2 build 93057
Multiple VMware hosted products with VMCI enabled are prone to a vulnerability that lets attackers execute arbitrary code. This issue affects Microsoft Windows-based hosts only.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successfully exploiting this issue can completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition.
This issue affects the following VMware products:
VMware Workstation prior to 6.0.4 build 93057
VMware Player prior to 2.0.4 build 93057
VMware ACE prior to 2.0.2 build 93057
Exploit / POC
VMware VMCI Arbitrary Code Execution Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
VMware VMCI Arbitrary Code Execution Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
References
VMware VMCI Arbitrary Code Execution Vulnerability
References:
References:
- VMware Homepage (VMware)
- VMSA-2008-0008 Updates to VMware Workstation, VMware Player, VMware ACE, VMware (VMware Security team
)