Fri, May 29 2009 13:13 Don

VMware Releases Security Advisory - May 29, 2009

VMware has released a security advisory to address multiple vulnerabilities in VMware Workstation, Player, ACE, Server, Fusion, ESX, and ESXi. The first of these vulnerabilities is due to a error in the VMware Descheduled Time Accounting driver. Exploitation of this vulnerability may result in denial of service in Windows-based virtual machines. The second vulnerability is due to a known error in the libpng package used by some VMware products. Exploitation of this vulnerability may allow an attacker to execute arbitrary code.

US-CERT encourages users and administrators to review the VMware security advisory and apply any necessary updates to help mitigate the risks

http://www.us-cert.gov/current/index.html#vmware_releases_security_advisory2

Filed under: