The 2009 Pwnie Nominee For Best Privilege Escalation Bug

VMware Display Function Host Code Execution from Guest (CVE-2009-1244)

Credit: VMware and Kostya Kortchinsky

For most people, VM escape exploits are like unicorns. They have heard about them, read about them, but they’ve never seen one. To assist with this, Immunity provides a nice video of Kostya’s CLOUDBURST exploit in action proving that, like unicorns, VM escape exploits are very real.
