Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

VMSA-2012-0011 VMware Workstation, Player, Fusion, ESXi and ESX patches address security issues.

Information

Severity

Severity

Critical

Family

Family

VMware Local Security Checks

CVSSv2 Base

CVSSv2 Base

9.3

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

Solution Type

Solution Type

Vendor Patch

Created

Created

11 years ago

Modified

Modified

5 years ago

Summary

The remote ESXi is missing one or more security related Updates from VMSA-2012-0011.

Insight

Insight

VMware Workstation, Player, Fusion, ESXi and ESX patches address security issues. a. VMware Host Checkpoint file memory corruption Input data is not properly validated when loading Checkpoint files. This may allow an attacker with the ability to load a specially crafted Checkpoint file to execute arbitrary code on the host. b. VMware Virtual Machine Remote Device Denial of Service A device (e.g. CD-ROM, keyboard) that is available to a virtual machine while physically connected to a system that does not run the virtual machine is referred to as a remote device. Traffic coming from remote virtual devices is incorrectly handled. This may allow an attacker who is capable of manipulating the traffic from a remote virtual device to crash the virtual machine.

Affected Software

Affected Software

Workstation 8.0.3 Workstation 7.1.5 Player 4.0.3 Player 3.1.5 Fusion 4.1.2 ESXi 5.0 without patch ESXi500-201206401-SG ESXi 4.1 without patch ESXi410-201206401-SG ESXi 4.0 without patch ESXi400-201206401-SG ESXi 3.5 without patch ESXe350-201206401-I-SG ESX 4.1 without patch ESX410-201206401-SG ESX 4.0 without patch ESX400-201206401-SG ESX 3.5 without patch ESX350-201206401-SG

Solution

Solution

Apply the missing patch(es). a. VMware Host Checkpoint file memory corruption Workaround - None identified Mitigation - Do not import virtual machines from untrusted sources. b. VMware Virtual Machine Remote Device Denial of Service Workaround - None identified Mitigation - Users need administrative privileges on the virtual machine in order to attach remote devices. - Do not attach untrusted remote devices to a virtual machine.

Common Vulnerabilities and Exposures (CVE)