Advertisement
Promo

Security threats Toolkit

IBM Virtualisation Special Report

Virtual-machine exploit lets attackers take over host

Matthew Broersma ZDNet.co.uk

Published: 09 Jun 2009 12:29 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Penetration-testing company Immunity has exploited a flaw in VMware software that allows malicious code running in a virtual machine to take over the host operating system.

Immunity included the attack code in an update to its commercial penetration-testing tool, Canvas 6.47, released on Tuesday last week. The attack code is in a module of the tool called Cloudburst.

Cloudburst uses a vulnerability in the virtual-machine display functions of VMware Workstation that can be exploited by a specially crafted video file. The malicious file, when executed within a virtual machine, could allow an intruder to take over the host operating system, according to security researchers.

The bug itself affects VMware Workstation 6.5.1 and earlier, or the associated Player versions. The software can be running on any host system, including Linux, according to VMware.

However, the Cloudburst exploit currently has certain limitations: it will only succeed on Workstation 6.5.0 or 6.5.1 or the associated Player versions. In addition, the guest and host must be Windows-based, among other requirements, Immunity said in its release notes.

The bug, which has been assigned the Common Vulnerabilities and Exploits (CVE) reference CVE-2009-1244, was disclosed in January, and VMware issued a patch in April. However, system administrators do not always keep their systems up to date with patches, Immunity said.

The bug is dangerous partly because it works with default VMware settings, according to security researchers. Secunia, a third-party security firm, gave the flaw a "highly critical" rating.

The flaw was discovered by Immunity researcher Kostya Kortchinsky, and Immunity published a video demonstrating its attack in April.

"The exploit is amazing," Immunity chief executive Dave Aitel said in a newslist post announcing the exploit video.

Two similar vulnerabilities came to light in 2007: a memory corruption vulnerability (CVE-2007-4496) and a bug in the Shared Folders implementation (CVE-2007-1744) that could allow a guest operating system to read or write files on the host system.

However, the first bug was not necessarily exploitable, while the second required a non-default configuration to be exploitable, security researchers said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
1 out of 1 people found this useful



More in this Special Report

Roundup: The reality of virtualisation special report

Roundup: The reality of virtualisation special report

Virtualisation has gone from curiosity to IT necessity. Find out what's happening at the cutting edge — and in daily use — in our special repor more

Virtualisation's 10 commandments of destruction

Virtualisation's 10 commandments of destruction

Like nuclear technology, virtualisation is being sold as safe yet powerful. But beware — do not ignore its disruptive potential more

Why virtualisation is struggling to keep up

Why virtualisation is struggling to keep up

The relentless increase of processors per chip will rapidly reach a point well beyond the levels for which key software has been engineered, says Carl Claunch more

VMware introduces 'operating system for the cloud'

VMware introduces 'operating system for the cloud'

VMware has announced its latest virtualisation suite, vSphere 4, which is designed for setting up and managing networked virtual processors within a company's datacentre more

Server consolidation: a tech guide

Server consolidation: a tech guide

Many modern datacentres are so full of equipment that it's impossible to add anything new without first making space for it. One way to free up valuable real estate is by consolidating existing servers into virtual machines or blade systems more

Citrix updates XenServer and Essentials

Citrix updates XenServer and Essentials

XenServer 5.5 promises to make it easier to convert virtual machines from one format to another, and to work better with third-party products more

IDC: Virtual servers set to overtake physical boxes

IDC: Virtual servers set to overtake physical boxes

IT departments in Western Europe will deploy more virtual machines than physical servers for the first time in 2009, according to IDC more

EMC's Tucci: Next big things in IT

EMC's Tucci: Next big things in IT

The data-storage and virtualisation company's chief executive Joe Tucci talks about four technologies that are shaking up the industry more

VMware exec demos fluid network switching

VMware exec demos fluid network switching

Chief technology officer Stephen Herrod explains what the additional features in the company's network-switching distribution will bring to virtualisation more

Do virtual servers really mean lower costs?

Do virtual servers really mean lower costs?

Assumptions about virtualisation cost savings need to be put on a firmer footing, says Cameron Haight more

vOptimizer Pro 2.1 review

vOptimizer Pro 2.1 review

This suite automatically reclaims over-allocated and under-utilised storage in Windows virtual machines. With SAN storage costing around £10/GB, Vizioncore's vOptimizer Pro could quickly pay for itself more

Company/Topic Alerts

Create a new alert from the list below:









Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters