PoC exploit Released for VMware Workstation guest-to-host escape Vulnerability (cybersecuritynews.com)
from cm0002@piefed.social to cybersecurity@infosec.pub on 04 Oct 03:07
https://piefed.social/post/1334060

#cybersecurity

threaded - newest

cron@feddit.org on 04 Oct 08:39 collapse

For users who cannot immediately update, a potential workaround is to disable the virtual Bluetooth device. This can be done by unchecking the “Share Bluetooth devices with the virtual machine” option in the virtual machine’s USB Controller settings.

As far as I know, it’s a best practice to enable as few virtual hardware devices as possible. For example, most VMWare guests will not need USB or bluetooth or camera support.