VMware Patched Critical Guest-to-Host Vulnerability Affecting VMware Workstation Pro
VMware has recently patched numerous bugs across multiple products. The most notable of all is a critical guest-to-host vulnerability affecting the VMware Workstation Pro.
WMware Patched Critical Vulnerability
Reportedly, a critical security vulnerability existed in the VMware Workstation Pro that targeted guest-to-host interaction. Specifically, the flaw allowed guest apps to execute commands on the host.
Sharing the details in an advisory, VMware elaborated that a critical use-after-free vulnerability (CVE-2020-3947) existed in Workstation and Fusion products.
VMware Workstation and Fusion contain a use-after vulnerability in vmnetdhcp… Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition of the vmnetdhcp service running on the host machine.The vendors labeled it a critical severity bug with a CVSS score of 9.3.
The bug first caught the attention of a Trend Micro ZDI researcher who then reported the matter to VMware. They have since fixed the flaw with the release of VMware Workstation v.15.5.2 and VMware Fusion v.11.5.2.
Other VMware Fixes
Alongside the above, the vendors also fixed two other vulnerabilities in their products.
The first of these is an important severity local Privilege escalation vulnerability in Cortado Thinprint (CVE-2020-3948). Affecting the VMware Workstation and Fusion, the vulnerability allowed local attackers to elevate privileges on a Linux guest VM by exploiting the flaw.
The vendors have fixed this bug since it had a CVSS score of 7.8 with the release of Workstation v.15.5.2 and Fusion v.11.5.2.
The other is also an important severity privilege escalation flaw (CVE-2019-5543) with a CVSS score of 7.3. The bug existed in VMware Horizon Client for Windows, VMRC for Windows and Workstation for Windows allowing exploitation by local attackers. The vendors fixed the flaw with the release of Horizon Client for Windows v.5.3.0, VMRC for Windows v.11.0.0, and Workstation for Windows v.15.5.2.
Users must ensure they upgrade to the latest patched versions to stay safe from potential exploitation.
Let us know your thoughts in the comments.
Posted from my blog with SteemPress : https://latesthackingnews.com/2020/03/17/vmware-patched-critical-guest-to-host-vulnerability-affecting-vmware-workstation-pro/
Leave VMware Patched Critical Guest-to-Host Vulnerability Affecting VMware Workstation Pro to:
Read more #arbitrarycodeexecution posts
Best Posts From twr
We have not curated any of twr's posts yet. But you can encourage our curation team to review posts by visiting them regularly and by referring other readers. Because we give priority to frequently read content.
More Posts From twr
- Will a VPN Protect Me From a Data Breach?
- Why DDoS Attacks Are Still One of the Biggest Cyberthreats
- Why Do Subdomain Lookups for Cybersecurity?
- What You Need To Know About Bitcoin Before Investing Your Money In It
- Massive Cyberattacks that Shook the World in 2020
- Data of 176 Million Pakistani Citizens Found For Sale On Dark Web
- Apple Patched Three Zero-Days With The Release Of iOS 14.4
- Watch Out For This Wormable Malware Spreading Via WhatsApp
- What Password Managers Are Safe to Use in 2021
- 7 Reasons to Choose an Outsourced Security Services Provider