If you use VMWare Workstation Player to run virtual machines on your devices, you may want to update the existing version of the application to the new version 17.5.
VMWare Workstation 17.5 Player fixes a security issue in the application, improves security by changing encryption scheme, and makes a number of other changes.
Users who are already running VMWare Workstation Player on their devices will receive an update notification the next time they run the client. The option to download and install the update is available, but it can also be skipped or postponed entirely.
Downloads are also already available on the official project website.
VMware Workstation 17.5 Player: the security patch
VMWare has published information about security issues fixed under VMSA-2023-0022 on its website. advice site. The security issue is an out-of-bounds read vulnerability “that exists in the host Bluetooth device sharing functionality with the virtual machine” according to VMWare.
An attacker with local administrator privileges in the virtual machine can exploit this to read privileged information “contained in the hypervisor memory from a virtual machine”. The security problem has a high severity rating.
Improving security
VMWare has moved from CBC mode for encrypted virtual machines to XTS. Any newly created virtual machine will automatically use XTS. Existing encrypted virtual machines may display an alert to the user, which includes an option to upgrade from CBC to XTS. Information about this process and potential issues is available on this site. support page.
Cipher Block Chaining is a commonly used algorithm, modified codebook mode based on XEX with ciphertext stealing is a modern standard.
Other improvements
VMWare Workstation Player 17.5 includes the following additional enhancements:
- Import and export virtual machines with a vTPM device
- Control virtual machines using VMRUN commands
- Manage power operations of encrypted virtual machines using the VMREST API
- VMware version 21 hardware
- Support up to 256 NVMe devices: 4 controllers and 64 devices per controller.
- Support for NVMe 1.3 in Windows 11 and Windows Server 2022.
The release fixes several issues in previous versions. The full list is available on the official release notes website.
Summary
Article name
VMware Workstation 17.5 Player resolves security issue
Description
VMware Workstation 17.5 Player is a security update for the application that fixes a security issue and improves security.
Author
Martin Brinkmann
Editor
Ghacks Tech News
Logo
Advertisement