Skip to main content

Security Week

VMware Patches ESXi Vulnerability That Earned Hacker $200,000

posted onDecember 6, 2019
by l33tdawg
Credit: Flickr

VMware on Thursday informed customers that it has released patches for a critical remote code execution vulnerability in ESXi that was disclosed recently at the Tianfu Cup hacking competition in China.

According to organizers of the Tianfu Cup, a member of the 360Vulcan team demonstrated a virtual machine escape and took control of the host operating system. The exploit only took 24 seconds to execute and earned the hacker $200,000, the highest single payout at the event.