<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>downgrade.org &#187; vulnerability</title>
	<atom:link href="http://downgrade.org/tag/vulnerability/feed" rel="self" type="application/rss+xml" />
	<link>http://downgrade.org</link>
	<description>The rantings and insight of an ethical hacker, coder and IT samurai.</description>
	<lastBuildDate>Mon, 05 Sep 2011 20:17:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>VM Escape</title>
		<link>http://downgrade.org/2009/04/15/vm-escape</link>
		<comments>http://downgrade.org/2009/04/15/vm-escape#comments</comments>
		<pubDate>Wed, 15 Apr 2009 20:17:11 +0000</pubDate>
		<dc:creator>Bryan Murphy</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[vm escape]]></category>
		<category><![CDATA[vmware]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://downgrade.org/?p=350</guid>
		<description><![CDATA[Whenever anyone speaks of virtual machine security the absolute worst case scenario is the dreaded &#8220;VM Escape&#8221;.  That is the ability of a malicious user to escape a virtual machines encapsulation and reach the host (or hypervisor).  This class of attack could potentially expose all other virtual machines running on this host. In the VM [...]]]></description>
			<content:encoded><![CDATA[<p>Whenever anyone speaks of virtual machine security the absolute worst case scenario is the dreaded &#8220;VM Escape&#8221;.  That is the ability of a malicious user to escape a virtual machines encapsulation and reach the host (or hypervisor).  This class of attack could potentially expose all other virtual machines running on this host.</p>
<p>In the VM world this type of vulnerability is an absolute worst case, but are very rare.</p>
<p>On April 10th <a title="VM Escape - CVE-2009-1244" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1244" target="_blank">CVE-2009-1244</a> was released stating that a number of VMWare products are vulnerable to VM escapes.</p>
<p>You should patch as soon as possible if you are running:</p>
<ul>
<li>VMware Workstation 6.5.1 and earlier</li>
<li>VMware Player 2.5.1 and earlier</li>
<li>VMware ACE 2.5.1 and earlier</li>
<li>VMware Server 1.x before 1.0.9 build 156507</li>
<li>VMware Server 2.x before 2.0.1 build 156745</li>
<li>VMware Fusion before 2.0.4 build 159196</li>
<li>VMware ESXi 3.5</li>
<li>VMware ESX 3.0.2, 3.0.3, and 3.5</li>
</ul>
<p>Per the CVE this vulnerability:</p>
<p style="padding-left: 30px;">allows guest OS users to execute arbitrary code on the host OS via unknown vectors, a different vulnerability than CVE-2008-4916.</p>
<p>This also validates why all of the best practice documents recommend that VMs of different sensitivity levels be run on physically separate hosts and/or clusters.</p>
<p>SANs Internet Storm Center <a title="SANS Internet Storm Center" href="http://isc.sans.org/diary.html?storyid=6190" target="_blank">reports that an exploit is available &#8216;in the wild&#8217;</a> for a fee.  They also provide a link to the following video of someone allegedly leveraging this exploit.</p>
<p><object width="267" height="267" data="http://www.immunityinc.com/documentation/cloudburst-vista.html" type="application/x-shockwave-flash"><param name="src" value="http://www.immunityinc.com/documentation/cloudburst-vista.html" /></object></p>
]]></content:encoded>
			<wfw:commentRss>http://downgrade.org/2009/04/15/vm-escape/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

