Tuesday, May 13, 2008
VMware ESX server 3 issue
I was have been busy at work developing a homegrown backup system for virtual machines on VMware ESX server 3 and while working the other day I came across a bug that causes the entire ESX server to crash. The error is in the way ESX server handles virtual disk files. I created a virtual disk delta file that was empty except for a special magic number at the beginning of the file. When that ESX server tried to power on the virtual machine containing my fake disk it caused the whole ESX host to dump its memory and crash.(Purple screen of death) Since this is only a local vulnerability it is not a very big deal. But, if used creatively it could be used to create a DOS of every virtual server running on the host. It could be delivered by tricking some one into downloading and installing a virtual appliance containing the specially crafted file. The VMware reps tell me that every fortune 500 company uses VMware ESX. Interesting...
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment