Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

The Guest Who Could: Exploiting LPE in VMWare Tools

Summary

PT SWARM details LPE flaws in VMware Tools' Windows VGAuth service (12.5.0) — a SYSTEM-level component for alias store, ticket and SAML auth on guest VMs, an overlooked guest-only attack surface.
Published
Collected

original ↗

Related coverage

back