Release date:
Updated on:
Affected Systems:
VMWare vSphere Client 5.x
VMWare vSphere Client 4.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66772
CVE (CAN) ID: CVE-2014-1209
VMware vCenter is a powerful centralized management component for hosts and virtual machines in the VMware vSphere suite.
In versions earlier than VMware vSphere Client 4.0, 4.1, 5.0 Update 3, and earlier than 5.1 Update 2, the Update of the Client file is not correctly verified, which allows remote attackers to trigger download and execution of arbitrary programs.
<* Source: Recurity Labs GmbH
Bundesamt Sicherheit
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
VMWare
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.vmware.com/security/
Http://www.vmware.com/security/advisories/VMSA-2014-0003.html