Skip to content

J-Security Center

Latest Attack Object Updates
  • IDP Daily Update #1312
    posted: 11/18/08
  • NSM Daily Update #1312
    posted: 11/18/08
  • Deep Inspection 5.3r5 and above, 5.4, 6.0 #1312
    posted: 11/18/08
  • Deep Inspection 5.1, 5.2, 5.3r4 and below #1300
    posted: 11/18/08
  • Deep Inspection 5.0 #1132
    posted: 04/01/08
  • Antivirus
    posted: 11/17/08

Title: VMware Workstation 'hcmon.sys' Local Denial Of Service Vulnerability

Severity: LOW

Description:

VMware Workstation is virtualization software that supports multiple operating platforms.

VMware Workstation is prone to a local denial-of-service vulnerability because the application fails to handle pointer data sent from usermode with 'METHOD_NEITHER'. An attacker can exploit this issue by sending IOCTL 0x8101232B to the '\\.\.hcmon' device driver.

Successfully exploiting this issue will allow attackers to crash the affected computer, denying service to legitimate users. Given the nature of this issue, attackers may also be able to run arbitrary code, but this has not been confirmed.

VMware Workstation 6.0.0.45731 is vulnerable; other versions may also be affected.

Affected Products:

  • VMWare Workstation 6.0.0.45731

References: