| OnlyPunjab | Law Forums | Links Directory | Fitness Forums |
Our Spicy Blog
World News
Gadget News
Infotech News
Entertainment News
UK News
News Archives
Culture News
ERP News
Science News
Asia News
Business News
Tech News
Webmaster News
Asia News
Hardware News
Security News
Legal News
South Asia
Africa News
Animal News
no load mutual funds
domain names
Onlypunjab Forums
Law Forums

We Have Recently Made Changes to Our Website, If you are unable to find something Specific, Please Search Below

Google
Web onlypunjab.com

Core Security Technologies Discovers Critical Vulnerability in VMware’s Desktop Virtualization Software
Publish Date : 2/25/2008 6:20:00 AM   Source : Software and ERP News Onlypunjab.com

Core Security Technologies, provider of CORE IMPACT, the most comprehensive product for performing enterprise security assurance testing, today issued an advisory disclosing a vulnerability that could severely impact organizations relying on VMware’s desktop virtualization software. This discovery demonstrates that thousands of companies with virtualized systems could unknowingly be exposing critical information assets that they otherwise sought to protect. Core Security today also released an exploit for this vulnerability, enabling customers to validate that it exists, prove that it can be exploited, and safely assess the consequences of an actual network intrusion.

Engineers from CoreLabs, the research arm of Core Security, discovered that an attacker could gain complete access to a host system by exploiting this vulnerability in VMware’s desktop software products. The vulnerability could allow an attacker to create or modify executable files on the host operating system.

“What’s most relevant about this vulnerability is it demonstrates how virtual environments can provide an open door to the underlying infrastructures that host them,” said Iván Arce, CTO at Core Security Technologies. “Organizations often adopt virtualization technologies with the assumption that the isolation between the host and guest systems will improve their security posture. This vulnerability provides an important wake-up call to security-concerned IT practitioners. It is signals that virtualization is not immune to security flaws and that ‘real’ environments aren’t safe simply because they sit behind virtual environments.”

Vulnerability Details

CoreLabs discovered that a malicious user or software running on a Guest system within VMware’s desktop software (VMware Player, Workstation and ACE) can break out of the isolated environment and gain full access to the Host computer system. The vulnerability was found while investigating a similar vulnerability in VMware Workstation disclosed by Greg McManus of IDefense Labs in March 2007 (CVE-2007-1744, VMware Workstation Shared Folders Directory Traversal Vulnerability).

CoreLabs researchers developing the exploit for CVE-2007-1744 realized that, by using a specially crafted PathName to access a VMware shared folder, it is possible to gain complete access to the Host’s file system. This includes, but is not limited to, creating or modifying executable files in sensitive locations. The vulnerability stems from improper validation of the PathName parameter passed by a potentially malicious program or user in the Guest system to VMware’s Shared Folders mechanism, which in turn passes it to the Host system’s file system.

Exploitation of path traversal vulnerabilities such as one found by CoreLabs, also commonly found in web server software and web applications, generally involve the specification of pathnames that include the “..” substring to escape out of folder access restriction. To prevent this type of attack, it is common to filter out the potentially malicious substring from input received from untrusted sources.

Vulnerable VMware products that implement the Shared Folders feature fail to properly sanitize malicious input in the PathName parameter. Although stricter input validation was implemented to fix the vulnerability disclosed previously (CVE-2007-1744), the shared folder mechanism still provides complete access to the underlying file system of the Host system due to improper handling of strings with multi-byte encodings.

The vulnerability affects VMware Workstation, Player and ACE software and it is only exploitable when Shared Folders are enabled (a default setting) and at least one folder on the Host system is configured for sharing. Organizations seeking an immediate workaround to mitigate risk should disable shared folders in all installations of the vulnerable software. If the Shared Folders feature cannot be fully disabled, configuring it to allow read-only access to the Host folder may still provide limited mitigation. However, because other exploitation scenarios may still exist, CoreLabs recommends that end users update to non-vulnerable versions of VMware Workstation, Player and ACE.

VMware has acknowledged this security problem and stated that it will address the issue within the release schedule of the affected products. To protect against potential attacks in the meantime, Core Security recommends that users immediately take one of the following actions:
Disable Shared Folders for all virtual machines that use the feature.
If the Shared Folders feature is required, configure it for read-only access.
If the Shared Folders feature is required, implement appropriate file system monitoring and access control mechanisms on the Host operating system.
Upgrade your VMware software to a non-vulnerable version.

For more information on this vulnerability and the systems affected, please view the CORE-2007-0930 Security Advisory, “Path Traversal Vulnerability in VMware's Shared Folders Implementation” at http://www.coresecurity.com/?action=item&id=2129.

About CoreLabs

CoreLabs, the research center of Core Security Technologies, is charged with anticipating the future needs and requirements for information security technologies. Research is conducted in several important areas of computer security including system vulnerabilities, cyber attack planning and simulation, source code auditing and cryptography. Results from these efforts include problem formalization, identification of vulnerabilities, novel solutions and prototypes for new technologies.

CoreLabs regularly publishes security advisories, technical papers, project information and shared software tools for public use at: http://www.coresecurity.com/corelabs/.

About Core Security Technologies

Core Security Technologies develops strategic solutions that help security-conscious organizations worldwide develop and maintain a proactive process for securing their IT infrastructure. The company’s flagship product, CORE IMPACT, is the most comprehensive product for performing enterprise security assurance testing. IMPACT evaluates servers, desktop systems, end users and web applications by identifying what resources are exposed. It enables organizations to determine if current security investments are detecting and preventing attacks.



More Onlypunjab.com News Stories


Chinese software managers to be trained in India         Publish Date : 1/28/2005 12:32:00 PM  
Some 1,000 software managers from south China's Shenzhen city are to undergo training in India to improve their communication skills and etiquette, reports Xinhua.

Kalam launches new software for blind         Publish Date : 1/27/2005 12:23:00 PM  
President A.P.J. Abdul Kalam Wednesday launched "Virtual Vision", a software for the blind, here on the occasion of India's 56th Republic Day.

InfoVista Reports Solid Second Quarter, Ahead of Top Line and Bottom Line Guidance         Publish Date : 1/26/2005 12:53:00 PM  
InfoVista (Euronext Paris: FR0004031649, NASDAQ: IVTA), the leading service-centric performance management software company today announced record financial results ....

SEGA Sells Visual Concepts Entertainment to Take-Two Interactive         Publish Date : 1/25/2005 10:25:00 AM  
SEGA(R) of America today confirmed that SEGA Corporation has agreed to transfer all common stock and related assets of Visual Concepts Entertainment (Visual Concepts)....

Transmeta Corporation Outlines Strategic Restructuring Plan         Publish Date : 1/24/2005 2:38:00 PM  
Transmeta Corporation (NASDAQ:TMTA), the leader in efficient computing, today provided an update on its plans to modify its current business model to focus on licensing ....

Digital River Announces Filing of Shelf Registration Statements         Publish Date : 1/15/2005 10:38:00 AM  
Digital River, Inc. (Nasdaq:DRIV) today announced that it has filed a universal shelf Registration Statement on Form S-3 and an acquisition shelf Registration Statement ....

Siebel Systems Completes Acquisition of edocs         Publish Date : 1/15/2005 10:34:00 AM  
Siebel Systems, Inc. (NASDAQ:SEBL), a leading provider of business applications software, today announced that it has closed its acquisition of edocs, Inc., a leading provider ...

DataMirror Adds Experienced Management to North American Sales Team         Publish Date : 1/14/2005 2:19:00 PM  
DataMirror(R) (TSX:DMC)(NASDAQ:DMCX) today announced that Mr. Paul Gilbert has been named Vice President of Sales for the United States and Canada.

Bocada Achieves Record Results in 2004         Publish Date : 1/14/2005 11:23:00 AM  
Bocada, Inc., the leading provider of data protection performance management software, today announced record results for its fiscal year ended December 31, 2004.

eBay to Acquire Kurant Assets         Publish Date : 1/14/2005 10:56:00 AM  
Kurant, a leading provider of e-business software for small and medium-sized businesses (www.kurant.com), and eBay, the World's Online Marketplace...

Total Results : 42  
More News (Opens in New Window) :    [1]   2   3   4   5      Next Page


News Archives | Asia News | World News | Gadget News | Entertainment News | Infotech News | UK News | Culture News | ERP News | Science News | Asia News | Business News | Hardware News | Security News | Legal News | South Asia | Africa News | Animal News | Canada News | Europe News | Health News | Middle East | Sports News | Advertising News | America News | Application News | Asia Pacific | Software News | Education News | Networking News | Technology News |
Entertainment News | Add Your Link to Our Directory | Travel News | Fitness News |

Post News About Your Company or Website Services Update on This Website Within 15 Hours
Discuss This Press Release in Forums, Get Views of Others on Story and Post Yours

alcoholism treatment

Canada News

Gadget News

Infotech News

Europe News

Health News

Middle East

Sports News

Advertising News

America News

Application News

Asia Pacific

Software News

Education News

Networking News

Technology News

Entertainment News

Add Your Link to Our Directory

Travel News

Fitness News

Onlypunjab Coop | Latest News | Reprint Articles | meditation techniques |

Copyrighted Material © Onlypunjab.com 1998 - 2007.      Contact Us with Suggestions / DMCA / Complaints / Corrections at Support Desk