Quantcast
Channel: VMware Communities : Discussion List - Virtual Machine, Guest OS and VM Tools
Viewing all articles
Browse latest Browse all 1961

VMware security advisory VMSA-2016-0001 relating to "shared Folders"

$
0
0

SO,  I just received this advisory from VMware in my inbox, and I don't quite understand how this is related to ESXi.   I'm aware of shared folders when working in VM workstation and fusion, I've done it, but since when is this a feature in ESXi?  If it is there, its escaped me all these years of working with the core infrastructure products..

 

Can someone please shed light on how this advisory effects VMs running on ESXi, and how to use this shared folders feature with VMs running on ESXi.

 

I do see the bulletin states you would need to have installed the complete version of VM tools, but still, haven't heard of this with ESXi and vCenter...  and I can't find any instructions on how to configure it with VMs running on ESXi.

 

  Bulletin details are below:

- ------------------------------------------------------------------------

 

                   VMware Security Advisory

 

Advisory ID: VMSA-2016-0001

 

Synopsis:    VMware ESXi, Workstation, Player, and Fusion updates

 

             address important guest privilege escalation vulnerability

 

Issue date:  2016-01-07

 

Updated on:  2016-01-07 (Initial Advisory)

 

CVE number:  CVE-2015-6933

 

1. Summary

 

   VMware ESXi, Fusion, Player, and Workstation updates address

 

   important guest privilege escalation vulnerability

 

2. Relevant Releases

 

   VMware ESXi 6.0 without patch ESXi600-201512102-SG

 

   VMware ESXi 5.5 without patch ESXi550-201512102-SG

 

   VMware ESXi 5.1 without patch ESXi510-201510102-SG

 

   VMware ESXi 5.0 without patch ESXi500-201510102-SG

 

 

   VMware Workstation prior to 11.1.2

 

   VMware Player prior to 7.1.2

 

   VMWare Fusion prior to 7.1.2

 

 

3. Problem Description

 

 

   Important Windows-based guest privilege escalation in VMware Tools

 

 

   A kernel memory corruption vulnerability is present in the VMware Tools

 

   "Shared Folders" (HGFS) feature running on Microsoft Windows. Successful

 

   exploitation of this issue could lead to an escalation of privilege in

 

   the guest operating system.

 

 

   VMware would like to thank Dmitry Janushkevich from the Secunia

 

   Research Team for reporting this issue to us.

 

 

   Note: This vulnerability does not allow for privilege escalation from

 

   the guest operating system to the host. Host memory can not be

 

   manipulated from the guest operating system by exploiting this flaw.

 

 

   The Common Vulnerabilities and Exposures project (cve.mitre.org) has

 

   assigned the identifier CVE-2015-6933 to this issue.

 

 

   Workarounds

 

   Removing the "Shared Folders" (HGFS) feature from previously installed

 

   VMware Tools will remove the possibility of exploitation.

 

 

   Column 4 of the following table lists the action required to

 

   remediate the vulnerability in each release, if a solution is

 

   available.

 

 

   VMware                         Product    Running   Replace with/

 

   Product                        Version    on        Apply Patch *

 

   =============                  =======    =======   =================

 

   VMware ESXi                    6.0        ESXi    

 

ESXi600-201512102-SG**

 

   VMware ESXi                    5.5        ESXi    

 

ESXi550-201512102-SG**

 

   VMware ESXi                    5.1        ESXi    

 

ESXi510-201510102-SG**

 

   VMware ESXi                    5.0        ESXi    

 

ESXi500-201510102-SG**

 

 

   VMware Workstation             12.x.x     Any       not affected

 

   VMware Workstation             11.x.x     Any       11.1.2

 

 

   VMware Player                  8.x.x      Any       not affected

 

   VMware Player                  7.x.x      Any       7.1.2

 

 

   VMware Fusion                  8.x.x      OSX       not affected

 

   VMware Fusion                  7.x.x      OSX       7.1.2

 


Viewing all articles
Browse latest Browse all 1961

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>