Email this article   Print article 


VMware Confirms ESX Server Hypervisor Source Code Leak

By Kevin McLaughlin
April 24, 2012    4:54 PM ET

VMware on Tuesday announced that a single file from its ESX server hypervisor source code has been posted online, and it held out the possibility that more proprietary files could be leaked in the future.

In a tersely worded blog post, Iain Mulholland, director of VMware's Security Response Center, said the posted ESX code and associated commentary was created between 2003 and 2004.

Mulholland did not provide additional details on the leaked code but said the fact that it has been made public does not necessarily put VMware customers at risk.

Given the large number of service providers that run vSphere, security issues in ESX could potentially have a broad and widespread impact, according to security researchers.

"A serious zero day to the hypervisor could be disastrous to a lot of customers," said Andrew Plato, president of Anitian Enterprise Security, a Beaverton, Ore.-based security solution provider.

Chris Ward, vice president of consulting and integration at Greenpages, a Kittery, Maine-based solution provider, said the potential risks -- to VMware and its customers -- depend on what type of ESX code has been compromised.

"If the code leaked was more service console level, versus the hypervisor or virtual machine manager (VMM) level code, then this is probably no big deal," Ward said. "However, if the code contains some of the more proprietary stuff, then it is a potential security risk -- as well as a competitive risk if someone like Oracle, Red Hat, or Microsoft can capitalize on it."

VMware says it is looking into the matter and will be canvassing its industry partners and developers in order to determine the source of the breach.

"VMware proactively shares its source code and interfaces with other industry participants to enable the broad virtualization ecosystem today," Mulholland said in the blog post. "We take customer security seriously and have engaged internal and external resources, including our VMware Security Response Center, to thoroughly investigate."

The ESX hypervisor has helped VMware take a dominant position in the server virtualization market. In 2008, VMware introduced a smaller, streamlined version of ESX -- called ESXi -- which is embedded in server motherboards.

VMware began using ESXi as its primary hypervisor in vSphere 5, in which it enables key features such as automatic deployment of hosts.

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Head-To-Head: Symantec Vs. McAfee In Endpoint Protection

McAfee and Symantec are archrivals with a firm grip on the North American security market. CRN pits both vendors' endpoint security products against each other and names a winner.

The 8 Steps Behind The Massive $45M Cyber Bank Heist

More than $45 million was stolen from banks in the U.S. and 19 other countries in a scheme that law enforcement is calling an international conspiracy to drain millions from bank accounts using stolen debit cards and PIN numbers. Here's how they did it.

Name Of The Game: Top 10 States For Identity Theft

A Federal Trade Commission report provides statistics on identity theft and fraud complaints in 2012. Learn which state has the dubious distinction of having the most victims.

  More Slide Shows




Related Videos
Loading...