Stories
Slash Boxes
Comments

SoylentNews is people

posted by janrinok on Monday September 19 2016, @03:03AM   Printer-friendly
from the is-that-virtual-junk? dept.

Late last week VMware delayed the release of Workstation 12.5 because of a bug it felt needed squashing before the code went live.

It turns out the desktop hypervisor doesn't have one: it has three. And all nasty.

Two derive from a dud installer. The first means "some DLL files [are] loaded by the application improperly."

"This issue may allow an attacker to load a DLL file of the attacker's choosing that could execute arbitrary code."

The second installer mess comes about because it "contains an insecure executable loading vulnerability that may allow an attacker to execute an exe file placed in the same directory as installer."

"Successfully exploiting this issue may allow attackers  to execute arbitrary code."

VMware has also 'fessed up to a problem that affects VMs running in Workstation that have virtual printing turned on. This flaw means "a Windows-based Virtual Machine to trigger a heap-based buffer overflow [and] may lead to arbitrary code execution in VMware Workstation running on Windows."


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 0) by Anonymous Coward on Monday September 19 2016, @04:00AM

    by Anonymous Coward on Monday September 19 2016, @04:00AM (#403611)

    Same here... I 'only' run windoze, because the driver for my USB thingie has no driver outside M$ world ...
    If that changes any day now, goodbye windoze (even in VM)

  • (Score: 3, Informative) by Arik on Monday September 19 2016, @04:04AM

    by Arik (4543) on Monday September 19 2016, @04:04AM (#403612) Journal
    Here you go: http://desowin.org/usbpcap/
    --
    If laughter is the best medicine, who are the best doctors?
    • (Score: 2) by Jeremiah Cornelius on Monday September 19 2016, @02:11PM

      by Jeremiah Cornelius (2785) on Monday September 19 2016, @02:11PM (#403763) Journal

      HA HA!

      Look at VMware, trying to build a package that covers-over a screen door on the Microsoft submarine!

      --
      You're betting on the pantomime horse...