News: 1709796607

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

VMware urges emergency action to blunt hypervisor flaws

(2024/03/07)


Hypervisors are supposed to provide an inviolable isolation layer between virtual machines and hardware. But hypervisor heavyweight VMware by Broadcom yesterday revealed its hypervisors are not quite so inviolable as it might like.

In a [1]security advisory the Broadcom business unit warned of four flaws.

The nastiest two – CVE-2024-22252 and 22253 – are rated 9.3/10 on VMware's Workstation and Fusion desktop hypervisors and 8.4 on the ESXi server hypervisor.

[2]

The flaws earned those ratings as they mean a malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code outside the guest. On Workstation and Fusion that code will run on the host PC or Mac. Under ESXi it will run in the VMX process that encapsulates each guest VM.

[3]

[4]

In an [5]FAQ , VMware rated the two flaws an emergency change, as defined by the IT Infrastructure Library.

Another vuln, CVE-2024-2225, is rated 7.1.

[6]

Workarounds for the flaws even apply to vSphere 6.x – a now unsupported version of VMware's flagship server virtualization platform.

Virtual USB controllers are the source of the problem for the three CVEs mentioned above. VMware's [7]workaround for the flaw is removing them from VMs.

Yet VMware's FAQ admits doing so "may not be feasible at scale" as "some supported operating systems require USB for keyboard & mouse access via the virtual console." Loss of USB passthrough functionality may be another unwanted consequence.

[8]

The FAQ adds: "That said, most Windows and Linux versions support use of the virtual PS/2 mouse and keyboard," and removing unnecessary devices such as USB controllers is recommended as part of the security hardening guidance VMware publishes.

Making matters worse, VMware also advised of CVE-2024-22254 – an out of bounds write vulnerability that could see a malicious actor with privileges within the VMX process trigger an out-of-bounds write, leading to an escape of the sandbox.

[9]Broadcom builds a SASE out of VMware VeloCloud and Symantec

[10]Citrix reveals invitation-only 'Platform' license

[11]The self-created risk in Broadcom's big VMware kiss-off

[12]Broadcom CEO pay award jumps 164% to $160.8 million

Guest-host escapes are the worst-case virtualization incident. These look significant, but short of total takeovers of the hypervisor that would allow an attacker to control fleets of VMs.

Interestingly, some of the flaws were discovered by researchers at 2023's Tianfu Cup Pwn Contest – China's equivalent of the Pwn2Own infosec attack-fest.

VMware thanked contest participants Jiang YuHao, Ying XingLei & Zhang ZiMing of Team Ant Lab – an outfit affiliated with Alibaba – and VictorV & Wei of Team CyberAgent. Also thanked were Jiaqing Huang and Hao Zheng from the TianGong Team of Legendsec at Qi'anxin Group, as they found some of the flaws independently. ®

Get our [13]Tech Resources



[1] https://www.vmware.com/security/advisories/VMSA-2024-0006.html

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/virtualization&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZemeYLKKzWZPVXzUFf-86QAAAFQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/virtualization&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZemeYLKKzWZPVXzUFf-86QAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/virtualization&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZemeYLKKzWZPVXzUFf-86QAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://core.vmware.com/resource/vmsa-2024-0006-questions-answers#which-products-are-affected

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/virtualization&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZemeYLKKzWZPVXzUFf-86QAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://kb.vmware.com/s/article/96682

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/virtualization&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZemeYLKKzWZPVXzUFf-86QAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2024/02/27/vmware_symantec_sase/

[10] https://www.theregister.com/2024/03/06/citrix_platform_hybrid_cloud_licenses/

[11] https://www.theregister.com/2024/02/26/opinon_column_broadcom_vmware/

[12] https://www.theregister.com/2024/02/28/broadcom_ceo_pay_award_jumps/

[13] https://whitepapers.theregister.com/



Remove USB devices

Mishak

Great, but what about those of use that need to use USB passthrough*? Is there going to be a "real" fix rolled out at some point?

* For example, I run some PC only software that uses USB hardware interfaces (CAN and the like) in a VM on Fusion.

Re: Remove USB devices

Yorick Hunt

Does anyone other than you have access to the VM? If not, you've nothing to worry about.

Jim Willsher

Updated my two ESXi hosts this morning. They are standalone, so I normally do esxcli software profile update etc. However this resulted in MemoryError.

Found a blog by the legendary William Lam:

https://williamlam.com/2024/03/quick-tip-using-esxcli-to-upgrade-esxi-8-x-throws-memoryerror-or-got-no-data-from-process.html

Solution is to download the offlne bundle and store in repo, then update from there

esxcli software profile update -p ESXi-8.0U2b-23305546-standard -d /vmfs/volumes/NUC3Primary/ISO/VMware-ESXi-8.0U2b-23305546-depot.zip

Posting ths just in case this helps anyone else.

"... And remember: if you don't like the news, go out and make some of
your own."
-- "Scoop" Nisker, KFOG radio reporter Preposterous Words