Skip to main content

VMware Products VI Client ActiveX Control Memory Corruption Vulnerability

Last Update Date: 7 Jun 2011 14:36 Release Date: 7 Jun 2011 5485 Views

RISK: High Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

A vulnerability has been reported in various VMware products, which can be exploited by malicious people to compromise a user's system.

 

The vulnerability is caused due to an unspecified error within the VI Client ActiveX controls, which can be exploited to cause a memory corruption by e.g. tricking a user into visiting a malicious website.


Impact

  • Remote Code Execution

System / Technologies affected

  • VMware Infrastructure 3.x
  • VMware VirtualCenter 2.x
  • VMware Virtual Infrastructure Client

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Replace the affected VI Client with the VI Client bundled with VirtualCenter 2.5 Update 6 or VirtualCenter 2.5 Update 6a. Also fixed in the VI Client version 2.0.2 Build 230598 and higher and version 2.5 Build 204931 and higher bundled with VMware Infrastructure 3.

Vulnerability Identifier


Source


Related Link