This may explain the failure to notify of a 0day, since it seemed to be exploited accidentally in the course of a more sophisticated operation.
But that doesn’t excuse the lack of disclosure IMO. If it’s so trivial you could accidentally exploit it, seems bad.
A cherry on the top: you need to pass a quest of registrations and approvals before you ever be able to have an opportunity to get access to any VMware software download. Good luck updating your software, folks.
I was able to get to a download page for the latest version after making an account and traversing some confusing stuff, but it did want my real name and address before it would give me the download.
They are but this a shit ton of money to be earned while doing so. VMWare is so cemented at companies that migration for many is going to be almost impossible.
>pre-1990's IBM that locked everything up into service contracts top to bottom
IBM still has a ton of those service contracts. It's small amount of their overall revenue but it's not nothing. 10 years from now, big F500 will still be on VMware paying insane amounts of money.
Not that containerization should be your only protection either, but generally I prefer random users not to have opportunity to just create and run arbitrary executables in default namespace.
chuckadams•4mo ago