<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: VMware Security</title>
	<atom:link href="http://wagnerelias.com/2008/06/12/vmware-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://wagnerelias.com/2008/06/12/vmware-security/</link>
	<description>BCP, BIA, DRP, Security Assessment, Risk Assessment, Security Developer</description>
	<lastBuildDate>Wed, 05 Oct 2011 13:05:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: João Rodolfo</title>
		<link>http://wagnerelias.com/2008/06/12/vmware-security/comment-page-1/#comment-420</link>
		<dc:creator>João Rodolfo</dc:creator>
		<pubDate>Tue, 17 Jun 2008 16:25:52 +0000</pubDate>
		<guid isPermaLink="false">http://wagnerelias.com/2008/06/12/vmware-security/#comment-420</guid>
		<description>Fala Wagner !

Certamente isso é para minimizar e detectar rapidamente problemas de segurança do tipo:

http://www.secuobs.com/secumail/snsecumail/msg10864.shtml
http://secunia.com/advisories/26890/

VMware Products Multiple Vulnerabilities

CRITICAL:
Less critical

IMPACT:
Security Bypass, Privilege escalation

WHERE:
Local system

OPERATING SYSTEM:
VMware ESX Server 3.x
VMware ESX Server 2.x
VMware Workstation 5.x
VMware Server 1.x
VMware Player 1.x
VMware ACE 1.x
VMware VIX API 1.x

DESCRIPTION:
Some vulnerabilities have been reported in multiple VMware Products, which can be exploited by malicious, local users to bypass certain security restrictions or to gain escalated privileges.

1) An error exists in the &quot;HGFS.sys&quot; driver included in the VMware Tools package. This can be exploited to execute arbitrary code with escalated privileges on a Windows guest machine.

2) An error in &quot;vmware-authd&quot; can be exploited to gain escalated privileges on a Linux host machine.

Abraços !&lt;div class=&quot;comment-remix-meta&quot;&gt;&lt;a href=&quot;#&quot; class=&quot;replyto&quot; onclick=&quot;replyto(&#039;420&#039;,&#039;Jo&#195;&#163;o Rodolfo&#039;); return false;&quot;&gt;Reply&lt;/a&gt;  - &lt;a href=&quot;#&quot; class=&quot;quote&quot; onclick=&quot;quote(&#039;420&#039;,&#039;Jo&#195;&#163;o Rodolfo&#039;,&#039;Fala Wagner !\r\n\r\nCertamente isso &#195;&#169; para minimizar e detectar rapidamente problemas de seguran&#195;&#167;a do tipo:\r\n\r\nhttp:\/\/www.secuobs.com\/secumail\/snsecumail\/msg10864.shtml\r\nhttp:\/\/secunia.com\/advisories\/26890\/\r\n\r\nVMware Products Multiple Vulnerabilities\r\n\r\nCRITICAL:\r\nLess critical\r\n\r\nIMPACT:\r\nSecurity Bypass, Privilege escalation\r\n\r\nWHERE:\r\nLocal system\r\n\r\nOPERATING SYSTEM:\r\nVMware ESX Server 3.x\r\nVMware ESX Server 2.x\r\nVMware Workstation 5.x\r\nVMware Server 1.x\r\nVMware Player 1.x\r\nVMware ACE 1.x\r\nVMware VIX API 1.x\r\n\r\nDESCRIPTION:\r\nSome vulnerabilities have been reported in multiple VMware Products, which can be exploited by malicious, local users to bypass certain security restrictions or to gain escalated privileges.\r\n\r\n1) An error exists in the \&quot;HGFS.sys\&quot; driver included in the VMware Tools package. This can be exploited to execute arbitrary code with escalated privileges on a Windows guest machine.\r\n\r\n2) An error in \&quot;vmware-authd\&quot; can be exploited to gain escalated privileges on a Linux host machine.\r\n\r\nAbra&#195;&#167;os !&#039;); return false;&quot;&gt;Quote&lt;/a&gt;&lt;/div&gt;</description>
		<content:encoded><![CDATA[<p>Fala Wagner !</p>
<p>Certamente isso é para minimizar e detectar rapidamente problemas de segurança do tipo:</p>
<p><a href="http://www.secuobs.com/secumail/snsecumail/msg10864.shtml" rel="nofollow">http://www.secuobs.com/secumail/snsecumail/msg10864.shtml</a><br />
<a href="http://secunia.com/advisories/26890/" rel="nofollow">http://secunia.com/advisories/26890/</a></p>
<p>VMware Products Multiple Vulnerabilities</p>
<p>CRITICAL:<br />
Less critical</p>
<p>IMPACT:<br />
Security Bypass, Privilege escalation</p>
<p>WHERE:<br />
Local system</p>
<p>OPERATING SYSTEM:<br />
VMware ESX Server 3.x<br />
VMware ESX Server 2.x<br />
VMware Workstation 5.x<br />
VMware Server 1.x<br />
VMware Player 1.x<br />
VMware ACE 1.x<br />
VMware VIX API 1.x</p>
<p>DESCRIPTION:<br />
Some vulnerabilities have been reported in multiple VMware Products, which can be exploited by malicious, local users to bypass certain security restrictions or to gain escalated privileges.</p>
<p>1) An error exists in the &#8220;HGFS.sys&#8221; driver included in the VMware Tools package. This can be exploited to execute arbitrary code with escalated privileges on a Windows guest machine.</p>
<p>2) An error in &#8220;vmware-authd&#8221; can be exploited to gain escalated privileges on a Linux host machine.</p>
<p>Abraços !
<div class="comment-remix-meta"><a href="#" class="replyto" onclick="replyto('420','Jo&Atilde;&pound;o Rodolfo'); return false;">Reply</a>  &#8211; <a href="#" class="quote" onclick="quote('420','Jo&Atilde;&pound;o Rodolfo','Fala Wagner !\r\n\r\nCertamente isso &Atilde;&copy; para minimizar e detectar rapidamente problemas de seguran&Atilde;&sect;a do tipo:\r\n\r\nhttp:\/\/www.secuobs.com\/secumail\/snsecumail\/msg10864.shtml\r\nhttp:\/\/secunia.com\/advisories\/26890\/\r\n\r\nVMware Products Multiple Vulnerabilities\r\n\r\nCRITICAL:\r\nLess critical\r\n\r\nIMPACT:\r\nSecurity Bypass, Privilege escalation\r\n\r\nWHERE:\r\nLocal system\r\n\r\nOPERATING SYSTEM:\r\nVMware ESX Server 3.x\r\nVMware ESX Server 2.x\r\nVMware Workstation 5.x\r\nVMware Server 1.x\r\nVMware Player 1.x\r\nVMware ACE 1.x\r\nVMware VIX API 1.x\r\n\r\nDESCRIPTION:\r\nSome vulnerabilities have been reported in multiple VMware Products, which can be exploited by malicious, local users to bypass certain security restrictions or to gain escalated privileges.\r\n\r\n1) An error exists in the \&quot;HGFS.sys\&quot; driver included in the VMware Tools package. This can be exploited to execute arbitrary code with escalated privileges on a Windows guest machine.\r\n\r\n2) An error in \&quot;vmware-authd\&quot; can be exploited to gain escalated privileges on a Linux host machine.\r\n\r\nAbra&Atilde;&sect;os !'); return false;">Quote</a></div>
]]></content:encoded>
	</item>
</channel>
</rss>

