Follow Us

Virtualisation users should expect more attacks

VMware’s mega patch release will be first of many.

VMware’s recent release of a large number of patches for its virtualisation offerings is likely to be the first of many, as hackers increasingly focus their attention on virtualised environments.

That is according to security vendor, Fortify Software, which is urging caution among those companies looking to adopt virtualisation technology. Last week,  the virtualisation market leader VMware warned of at least 16 vulnerabilitiesconcerning VMware ACE, VMware Server, VMware ESX, VMware Workstation and VMware Player. The advisory also included links to a number of patches.

The US Computer Emergency Readiness Team (US-CERT) meanwhile said these vulnerabilities could allow hackers to execute arbitrary code, cause a denial-of-service condition, access the system with elevated privileges, or obtain sensitive information. "With the dramatic fall in processor prices over the last 12 months and the amplifying effects of the credit crunch, many companies are reviewing their IT resources and concluding that virtual servers are a highly cost-effective and business-efficient way to go," said Rob Rachwald, Fortify's director of product marketing.

"A typical major business may find that VMware gives them access to, say, 16 virtual servers when they only have 12 physical servers. This is a real cost-saver and also allows companies to start taking out more innovative software licences as well," he added.

According to Rachwald, this is why so many major organisations were going down the virtual server route. But he warns the problem comes about because many conventional IT security applications do not fully protect virtual server users. "It's a whole new security ballgame, which is why we urge anyone contemplating migrating over to the benefits of a virtual server system to review their IT security systems," said Rachwald. It's also one of the reasons why we predict that virtual server patches will become commonplace in the months ahead," he explained.

Meanwhile, another security vendor admits it has not yet seen any specific attacks on virtualised announcements, but nevertheless feels that an attack may not be far off as some people think.

People are looking at virtualisation for sorts of reasons, but to the best of my knowledge, we have not seen any wholesale attack on virtualised environments to date said David Emm, senior technology consultant at Kaspersky Lab.

That said, any commonly used system does become a juicy target for these guys,” he told Techworld. "For example, it used to be said that Internet Explorer was less secure than Firefox, but as more and more people use Firefox, we are seeing more and more Firefox vulnerabilities. The same will be true for virtualised environments", he said.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *