You are absolutely deluded, if not stupid, if you think that a worldwide collection of software engineers who can't write operating systems or applications without security holes, can then turn around and suddenly write virtualization layers without security holes. -- Theo de Raadt
Escaping VMware Workstation Through COM1
11–15 of 15 posts
Re: Escaping VMware Workstation Through COM1
#12Is this a bug in VMware or a bug in Windows?
Re: Escaping VMware Workstation Through COM1
#13Is this a bug in VMware or a bug in Windows?
VMWare. It takes advantage of the fact that VMWare links guest VMs to the host's printers by default and takes advantage of that link. The patch from VMWare even applied to VMWare Fusion even though there hasn't been anything published on getting this to work in OSX.
Re: Escaping VMware Workstation Through COM1
#14Remind me: Are modern hypervisors meant to securely contain guests? Because they advertise their presence pretty loudly, and there's nothing which motivates a jail-break like reminding the inmate they're in a cell.
Yes, they are. A common use case of hypervisors is to split up a large server between multiple renters, who demand a hypervisor which won't let other renters hack them.
Re: Escaping VMware Workstation Through COM1
#15I disable any hardware in VMware guests that I don't need, like printers, speakers, or USB devices, to avoid exploits like this.
The VENOM vulnerability that affected the Floppy Drive didn't require that you had it enabled to be exploited: http://news.softpedia.com/news/11-Year-Old-Bug-in-Virtual-Fl...