Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
The issue is new, different from the vulnerability in a guest virtual device driver that was patched by VMware earlier this week. That earlier flaw could cause a potential denial-of-service, and affected Workstation, Player, ACE, Server, ESX and ESXi virtualisation products.One of the reasons this new vulnerability was labeled "critical" is that it could affect the underlying host operating system in a virtual environment.“A critical vulnerability in the virtual machine display function might allow a guest operating system to run code on the host,” the VMware advisory said.The VMware advisory lists a number of VMware versions that are affected, and whether the patches will properly address the vulnerability. But apparently, some users who have older versions may not be helped.“Depending on your version, your only option may be to upgrade rather than patch,” wrote Steve Hall, handler at the SANS Internet Storm Center, on the organisation's blog.The typical way to apply patches to ESXi hosts is through the VMware Update Manager, but ESXi hosts can also be updated by downloading a single offline download file, according to VMware.See original article on scmagazineus.com
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.