ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

VMware security bug exposed on eve of VMworld

Peter Judge ZDNet.co.uk

Published: 25 Feb 2008 14:00 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

VMware has failed to fix a severe bug in its virtualisation software, which can expose users' critical information, according to security vendor Core Security Technologies, which is releasing software that demonstrates the problem.

The announcement shows that virtualisation software is just as vulnerable as any other software, according to Core, and comes in the week of the vendor's VMworld event in Cannes, where VMware is expected to announce an important security initiative in partnership with other major companies.

Core has released proof-of-concept exploit software, which it says demonstrates a serious flaw in VMware's desktop virtualisation software that could give hackers control of virtualised systems, and which it claims VMware has been aware of for four months.

The security vendor is releasing the exploit in the week of the VMworld event in the hope that publicity will force VMware to take action, and to make users aware of the problem and enable them to "safely assess the consequences of an actual network intrusion", and apply a simple workaround to avoid the problem.

The vulnerability could allow an attacker to create or modify executable files on the host operating system, through weaknesses in VMware's shared folders feature. Hackers can use a specially crafted PathName to access a VMware shared folder, because VMware does not properly validate PathNames, according to Iván Arce, chief technology officer at Core.

The demonstration reveals that virtualisation environments are no safer than any other software environment, according to Arce: "Organisations often adopt virtualisation technologies with the assumption that the isolation between the host and guest systems will improve their security posture. This vulnerability provides an important wake-up call to security-concerned IT practitioners. It signals that virtualisation is not immune to security flaws and that 'real' environments aren't safe simply because they sit behind virtual environments."

CoreLabs staff found the vulnerability in October, while investigating a similar vulnerability in VMware Workstation disclosed by Greg McManus of IDefense Labs in March 2007. "Since October we have been exchanging emails with the VMware security team," said Arce. "The fix was supposed to be released in December, then January, then February. The workaround is simple and easy, so rather than continue to wait, we felt we should inform the users, and rhen wait for an official response."

To avoid the flaw, users have to disable shared folders and use alternative methods to share files, said Arce: "If they need to transfer files, there are other ways to do this. It shouldn't be too difficult." If they need shared folders, it is safe to configure it for read-only access and/or use file system monitoring on the host operating system.

Shared folders is turned on by default, so most VMware users could be vulnerable, according to Core. Despite VMware's delays, Arce believes the company is on the right track: "This is the first time we have dealt with VMware, and I think they do have the right skill set in terms of security," he told ZDnet. "I think they could improve their processes, but compared to other vendors they are not the worst or the best. Virtualisation is no more secure than any other software."

"Path traversal vulnerabilities" like this, also found in web server software and web applications, generally involve the specification of pathnames that include the ".." substring to escape out of folder access restriction. To prevent this type of attack, it is common to filter out the potentially malicious substring from input received from untrusted sources, according to Core's release.

VMware is preparing its own security initiative, called VMsafe, to be launched at VMworld, according to reports by Reuters, in which unnamed sources say the company is working with Symantec, McAfee, IBM's ISS division, Check Point and the RSA security unit of VMware parent EMC.

VMware did not respond to requests for information by press time.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
10 out of 10 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

GBS-0088233 CRM Infrastructure Architect

Your responsibilities will include: - Working with IBM Strategy Consultants and Application Architects and our clients to explore optimal platforms ...

Systems Engineer

The use of virtualisation in a production environment will require diligence and careful configuration management. Maintain an up-to-date knowledge ...

Network Security Lead

Understanding and working knowledge of various Government levels of security clearence for networks Understanding and experience of Virtualisation ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment