Significant virtual machine vulnerability has been hiding in floppy disk code for 11 years
CrowdStrike researchers announced this morning that they have discovered a buffer overflow vulnerability in many of today’s most popular virtual machine platforms that could potentially allow hackers access to the host.
They named the vulnerability VENOM — Virtualized Environment Neglected Operations Manipulation — because it takes advantage of long-neglected code, the virtual floppy disk controller.
Tags:
Story added 13. May 2015, content source with full text you can find at link above.