Skip to main content

VMware patches man-in-the-middle vSphere vuln

  • April 12, 2014
  • 1 reply
  • 1165 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
VMware has released an update to its vSphere Client which addresses a potential – but hard to target – man-in-the-middle vulnerability for the virtualization tool.

The company said that users running vSphere Client 4.0, 4.1, 5.0, and 5.1 for Windows were vulnerable to a flaw that allows the client to download and install untrusted updates. Were an attacker to exploit the flaw, VMware said that users could be subject to remote code execution attacks via a malicious link or redirect.

Systems running vSphere Client 5.5 are not vulnerable to the flaw.
 
Full Article

1 reply

Miquell
Community Leader
  • Community Leader
  • 828 replies
  • April 12, 2014
Thanks for the info!
 
Mike

Reply