Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Patch now: VMware Tools for Windows root holes fixed in update
The Register ^ | 8 Jan 2016 at 01:51 | Richard Chirgwin

Posted on 01/14/2016 7:32:59 PM PST by Utilizer

VMware sysadmins, get patching: the virtualisation outfit has released updates to its ESXi, Fusion, Player and Workstation software to block out a privilege-escalation vulnerability.

The patch applies to VMware Windows Workstation versions before 11.1.2, Player and Fusion versions prior to 7.1.2, and various ESXi versions depending on their patch level: VMware ESXi 6.0 without patch ESXi600-201512102-SG VMware ESXi 5.5 without patch ESXi550-201512102-SG VMware ESXi 5.1 without patch ESXi510-201510102-SG VMware ESXi 5.0 without patch ESXi500-201510102-SG

CVE-2015-6933 is a kernel memory corruption vulnerability in the tools' Shared Folders feature that can be exploited by software to escalate its privileges within a guest. VMware notes that the programming blunder cannot be exploited to escape from a guest to a host.

It was picked up by Secunia's Dmitry Janushkevich, and the CVE (common vulnerabilities and exposures) database entry was reserved in September 2015.

If you can't run the patches right away, disabling the Shared Folders feature (HGFS) removes the exploitation possibility.

(Excerpt) Read more at theregister.co.uk ...


TOPICS: Computers/Internet
KEYWORDS: roothack; security; vmware; windows; windowspinglist
VMware users beware!
1 posted on 01/14/2016 7:33:00 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer

I don’t know a single admin who enables the feature anyway. By concept alone, it’s a bad idea and always was... bug or not.


2 posted on 01/14/2016 7:40:27 PM PST by FunkyZero (... I've got a Grand Piano to prop up my mortal remains)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored; Utilizer

Ping for Windows users using VMWare. . . there’s a vulnerability that needs attention.


3 posted on 01/14/2016 7:46:45 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Thanks for the ping, I’ll have to get it in the morning, can’t post to the list right now....


4 posted on 01/14/2016 8:03:34 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 3 | View Replies]

To: Swordmaker

Thanks, mate. I was intending to ping dgr but got sidetracked so appreciate you pinging first.

Cheers!


5 posted on 01/14/2016 8:07:35 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Utilizer

But hypervisors can’t get infected. /sarcasm


6 posted on 01/14/2016 8:47:52 PM PST by ConservativeMind ("Humane" = "Don't pen up pets or eat meat, but allow infanticide, abortion, and euthanasia.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Don’t allow guests...


7 posted on 01/14/2016 9:28:54 PM PST by Vendome (Don't take life so seriously-you won't live through it anyway - "Enjoy Yourself" ala Louis Prima)
[ Post Reply | Private Reply | To 1 | View Replies]

To: FunkyZero
I don’t know a single admin who enables the feature anyway.

Yep. Too many better alternatives. Some of the newer SysAdmins want to snatch everything that's shiny. This is why not.

8 posted on 01/14/2016 9:36:17 PM PST by Billthedrill
[ Post Reply | Private Reply | To 2 | View Replies]

To: FunkyZero

Not all sysadmins are Great SysAdmins.

Shiiete happens, and you might be surprised at just how many compromised systems there are out there at any given moment.

Plus, VMware is getting more and more popular as time goes by, so some mistakes are bound to cause problems. Here is good info on one such ‘problem’.

Pass the word, won’t you now. :)


9 posted on 01/14/2016 10:05:04 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 2 | View Replies]

To: rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; amigatec; Ernest_at_the_Beach; ...

10 posted on 01/15/2016 12:38:07 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: FunkyZero

...you don’t use VMware tools on your Windows systems?! That’s literally the driver package for the VMware hardware abstraction layer.


11 posted on 01/15/2016 4:13:22 AM PST by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: rarestia; FunkyZero

Nevermind. You were talking about the Shared Folders functionality. Sorry for the impulsive response.


12 posted on 01/15/2016 4:16:14 AM PST by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Swordmaker; Utilizer; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; AppyPappy; ...
Using VMware? Time to Patch it! ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to Swordmaker and Utilizer for the ping!!

13 posted on 01/15/2016 5:34:25 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 3 | View Replies]

To: Utilizer

I’ve been trying to get my vmware tools updated on my work laptop since I reloaded the damned thing. The host is a laptop running craptastic Win 7. The first problem is that I can’t even get the file menu to display in the vmware application. I’ve searched the internet and have found craploads of articles on how to enable it in IE, and windowz explorer, but how do I get the file menu to display in other application?

I have no problem installing the tools from my Linux workstation. I just updated my Linux “Workstation” copy to 11.1.3. Guess I’ll test to see if installing the latest copy of tools there will be recognised on the windows host.


14 posted on 01/15/2016 8:11:27 AM PST by zeugma (Want to know what freedom smells like? Hoppes #9.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

I have not had a chance to play with VMware under the ‘doze platform yet so I am afraid I cannot help you there.

I do plan to work with it in Linux after I finish reinstalling a couple of machines but it will be a Virtual ‘Doze running in Linux so just the opposite of what you are running.

Perhaps someone else can be of assistance.

Cheers!


15 posted on 01/15/2016 6:47:54 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 14 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson