RETIRED: VMware Multiple Products SVGA II FIFO 3D Capabilities Code Execution Vulnerability
BID:35866
Info
RETIRED: VMware Multiple Products SVGA II FIFO 3D Capabilities Code Execution Vulnerability
| Bugtraq ID: | 35866 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 29 2009 12:00AM |
| Updated: | Jul 30 2009 04:45PM |
| Credit: | Immunity |
| Vulnerable: |
VMWare Workstation 6.5.2 VMWare Workstation 6.5.1 VMWare Workstation 6.5 build 118166 VMWare Workstation 6.0.5 build 109488 VMWare Workstation 6.0.5 VMWare Workstation 6.0.4 build 93057 VMWare Workstation 6.0.4 VMWare Workstation 6.0.3 Build 80004 VMWare Workstation 6.0.3 VMWare Workstation 6.0.2 VMWare Workstation 6.0.1 VMWare Workstation 6.0 VMWare Workstation 6.5.2 build 156735 VMWare Workstation 6.0.0.45731 VMWare Player VMWare ESXi Server 3.5 ESXe350-20090440 VMWare ESXi Server 3.5 VMWare ESX Server 3.0.3 ESX303-200905401-SG VMWare ESX Server 3.0.3 VMWare ESX Server 3.0.3 VMWare ESX Server 3.0.2 ESX-1008420 VMWare ESX Server 3.0.2 VMWare ESX Server 3.0.1 VMWare ESX Server 3.0 VMWare ESX Server 2.5.5 patch 9 VMWare ESX Server 2.5.5 patch 8 VMWare ESX Server 2.5.5 patch 6 VMWare ESX Server 2.5.5 patch 4 VMWare ESX Server 2.5.5 patch 2 VMWare ESX Server 2.5.5 patch 13 VMWare ESX Server 2.5.5 patch 12 VMWare ESX Server 2.5.5 patch 11 VMWare ESX Server 2.5.5 patch 10 VMWare ESX Server 2.5.5 VMWare ESX Server 2.5.4 Patch 5 VMWare ESX Server 2.5.4 Patch 3 VMWare ESX Server 2.5.4 patch 21 VMWare ESX Server 2.5.4 patch 19 VMWare ESX Server 2.5.4 Patch 17 VMWare ESX Server 2.5.4 Patch 16 VMWare ESX Server 2.5.4 patch 15 VMWare ESX Server 2.5.4 patch 13 VMWare ESX Server 2.5.4 Patch 10 VMWare ESX Server 2.5.4 Patch 1 VMWare ESX Server 2.5.4 VMWare ESX Server 2.5.3 Patch 8 VMWare ESX Server 2.5.3 Patch 7 VMWare ESX Server 2.5.3 Patch 6 VMWare ESX Server 2.5.3 Patch 5 VMWare ESX Server 2.5.3 Patch 4 VMWare ESX Server 2.5.3 Patch 13 VMWare ESX Server 2.5.3 VMWare ESX Server 2.5.2 VMWare ESX Server 2.5 VMWare ESX Server 2.1.3 Patch 8 VMWare ESX Server 2.1.3 Patch 5 VMWare ESX Server 2.1.3 Patch 4 VMWare ESX Server 2.1.3 Patch 2 VMWare ESX Server 2.1.3 VMWare ESX Server 2.1.2 VMWare ESX Server 2.1.1 VMWare ESX Server 2.1 VMWare ESX Server 2.0.2 Patch 8 VMWare ESX Server 2.0.2 Patch 5 VMWare ESX Server 2.0.2 Patch 4 VMWare ESX Server 2.0.2 Patch 2 VMWare ESX Server 2.0.2 VMWare ESX Server 2.0.1 build 6403 VMWare ESX Server 2.0.1 VMWare ESX Server 2.0 build 5257 VMWare ESX Server 2.0 VMWare ESX Server 1.5.2 VMWare ESX Server 4.0 VMWare ESX Server 3.5 ESX350-200906407 VMWare ESX Server 3.5 ESX350-200904401 VMWare ESX Server 3.5 VMWare ESX Server 2.5.5 patch 5 VMWare ESX Server 2.5.3 Patch 2 VMWare ESX Server 2.5.2 Patch 4 VMWare ESX Server 2.1.3 Patch 1 VMWare ESX Server 2.0.2 Patch 1 VMWare ESX 2.1.3 |
| Not Vulnerable: | |
Discussion
RETIRED: VMware Multiple Products SVGA II FIFO 3D Capabilities Code Execution Vulnerability
Multiple VMware products are prone to a code-execution vulnerability that affects the 'rect_copy()' function of the SVGA II FIFO 3D capability on the guest operating system.
An attacker in the guest operating system can exploit this issue to execute arbitrary code in the host system. This may facilitate a complete compromise of the host computer.
The following products are affected (specific versions aren't yet known):
VMware Workstation
VMware Server
VMware ESX
Additional VMware hosted products may also be vulnerable.
NOTE: This issue may similarly affect other FIFO 3D functions; details have not yet been revealed.
We will update this BID when further details are disclosed.
NOTE: This BID is being retired because it is a duplicate of BID 34471 (VMware Multiple Hosted Products Display Function Code Execution Vulnerability).
Multiple VMware products are prone to a code-execution vulnerability that affects the 'rect_copy()' function of the SVGA II FIFO 3D capability on the guest operating system.
An attacker in the guest operating system can exploit this issue to execute arbitrary code in the host system. This may facilitate a complete compromise of the host computer.
The following products are affected (specific versions aren't yet known):
VMware Workstation
VMware Server
VMware ESX
Additional VMware hosted products may also be vulnerable.
NOTE: This issue may similarly affect other FIFO 3D functions; details have not yet been revealed.
We will update this BID when further details are disclosed.
NOTE: This BID is being retired because it is a duplicate of BID 34471 (VMware Multiple Hosted Products Display Function Code Execution Vulnerability).
Exploit / POC
RETIRED: VMware Multiple Products SVGA II FIFO 3D Capabilities Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RETIRED: VMware Multiple Products SVGA II FIFO 3D Capabilities Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: VMware Multiple Products SVGA II FIFO 3D Capabilities Code Execution Vulnerability
References:
References:
- CLOUDBURST (Immunity)
- VMware Homepage (VMware)