Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.103495
Categoría:VMware Local Security Checks
Título:VMware ESXi/ESX patches address security issues (VMSA-2012-0011)
Resumen:The remote ESXi is missing one or more security related Updates from VMSA-2012-0011.
Descripción:Summary:
The remote ESXi is missing one or more security related Updates from VMSA-2012-0011.

Vulnerability Insight:
a. VMware Host Checkpoint file memory corruption

Input data is not properly validated when loading Checkpoint files. This may
allow an attacker with the ability to load a specially crafted Checkpoint file
to execute arbitrary code on the host.

b. VMware Virtual Machine Remote Device Denial of Service

A device (e.g. CD-ROM, keyboard) that is available to a virtual machine while
physically connected to a system that does not run the virtual machine is
referred to as a remote device.

Traffic coming from remote virtual devices is incorrectly handled. This may
allow an attacker who is capable of manipulating the traffic from a remote
virtual device to crash the virtual machine.

Affected Software/OS:
ESXi 5.0 without patch ESXi500-201206401-SG

ESXi 4.1 without patch ESXi410-201206401-SG

ESXi 4.0 without patch ESXi400-201206401-SG

ESXi 3.5 without patch ESXe350-201206401-I-SG

ESX 4.1 without patch ESX410-201206401-SG

ESX 4.0 without patch ESX400-201206401-SG

ESX 3.5 without patch ESX350-201206401-SG

Solution:
Apply the missing patch(es).

a. VMware Host Checkpoint file memory corruption

Workaround - None identified

Mitigation - Do not import virtual machines from untrusted sources.

b. VMware Virtual Machine Remote Device Denial of Service

Workaround - None identified

Mitigation - Users need administrative privileges on the virtual machine in
order to attach remote devices. - Do not attach untrusted remote devices to a
virtual machine.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2012-3288
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17178
Common Vulnerability Exposure (CVE) ID: CVE-2012-3289
CopyrightCopyright (C) 2012 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.