VMware Products VI Client ActiveX Control Memory Corruption Vulnerability
Last Update Date:
7 Jun 2011 14:36
Release Date:
7 Jun 2011
6375
Views
RISK: High Risk
TYPE: Clients - Productivity Products
A vulnerability has been reported in various VMware products, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an unspecified error within the VI Client ActiveX controls, which can be exploited to cause a memory corruption by e.g. tricking a user into visiting a malicious website.
Impact
- Remote Code Execution
System / Technologies affected
- VMware Infrastructure 3.x
- VMware VirtualCenter 2.x
- VMware Virtual Infrastructure Client
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Replace the affected VI Client with the VI Client bundled with VirtualCenter 2.5 Update 6 or VirtualCenter 2.5 Update 6a. Also fixed in the VI Client version 2.0.2 Build 230598 and higher and version 2.5 Build 204931 and higher bundled with VMware Infrastructure 3.
Vulnerability Identifier
Source
Related Link
Share with