VMwareÐéÄâ»úÌÓÒÝÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-11-13

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-6981 £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2018-6982 £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


VMware vSphere ESXi (ESXi)

VMware Workstation Pro / Player (Workstation)

VMware Fusion Pro, Fusion (Fusion)


Îó²î¸ÅÊö


VMwareÒÑΪ¸ÃÐéÄâ»ú£¨VM£©ÌÓÒÝÖ÷ÒªÎó²î£¨CVE-2018-6981ÓëCVE-2018-6982£©Ðû²¼Çå¾²²¹¶¡ £¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÓÉÑо¿Ô±ÕÅìÍÓî½üÆÚÔÚÖйúGeekPwn2018ºÚ¿Í´óÈüÖз¢Ã÷¡£¡£¡£¡£


ÕâЩ³ÌÐò¹ýʧÊÇÓÉvmxnet3ÐéÄâÍøÂçÊÊÅäÆ÷ÖÐδ³õʼ»¯µÄ¿ÍÕ»ÄÚ´æÊ¹Óùýʧµ¼ÖµÄ¡£¡£¡£¡£¶øÕâЩ¹ýʧ½öÔÚvmxnet3ÊÊÅäÆ÷ÔÊÐíµÄÇéÐÎϲſÉÓᣡ£¡£¡£


ÓÉVMwareÐû²¼µÄ֪ͨ¿ÉÖª £¬£¬£¬£¬£¬£¬£¬¡°VMware ESXi¡¢FusionÓëWorkstationµÄvmxnet3ÐéÄâÍøÂçÊÊÅäÆ÷ÖаüÀ¨Î´³õʼ»¯µÄ¿ÍÕ»ÄÚ´æÊ¹Óᣡ£¡£¡£ÆôÓÃvmxnet3ʱ £¬£¬£¬£¬£¬£¬£¬¸ÃÎÊÌâ»áÔÊÐíÐéÄâ»úÔÚËÞÖ÷»úÉÏÖ´ÐдúÂë¡£¡£¡£¡£ËùÓеÄvmxnet3¾ùÊÜ´ËÎÊÌâÓ°Ïì¡£¡£¡£¡£¡±


ÐéÄâÖ÷»ú¿ÉʹÓÃÎó²î¡°CVE-2018-6981¡±ÔÚÖ÷»úÉÏÖ´ÐÐí§Òâ´úÂë £¬£¬£¬£¬£¬£¬£¬Ó°ÏìVMware ESXi¡¢FusionÓëWorkstation²úÆ·¡£¡£¡£¡£¶øÎó²î¡°CVE-2018-6982¡±¿Éµ¼Ö´ÓÖ÷»úµ½ÐéÄâ»úµÄÐÅϢй¶ £¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÖ»Ó°ÏìESXi¡£¡£¡£¡£


¸ÃÎó²îºÜÊÇÖ÷Òª £¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÕâÊÇר¼ÒÊ×´ÎÀÖ³ÉʵÑéÌÓÒÝVMwareESXi £¬£¬£¬£¬£¬£¬£¬²¢ÔÚËÞÖ÷ϵͳÖлñÈ¡root shell¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP £¬£¬£¬£¬£¬£¬£¬GeekPwn2018 £¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄ¹¥»÷չʾ¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



ÊÖ¹¤×Ô²é

ÐéÄâ»úÊÇ·ñʹÓÃÁËvmxnet3¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÐÞ¸´½¨Òé


ÊÜCVE-2018-6981Ó°Ïì²úÆ·¼°¿ÉÌæ»»/²¹¶¡°æ±¾


²úÆ·

°æ±¾

ÔËÐÐÆ½Ì¨

ÑÏÖØË®Æ½

Ìæ»»Îª/Ó¦Óò¹¶¡

ESXi

6.7

ESXi

Critical

ESXi670-201811401-BG

ESXi

6.5

ESXi

Critical

ESXi650-201811301-BG

ESXi

6.0

ESXi

Critical

ESXi600-201811401-BG

Workstation

15.x

ËùÓÐ

Critical

15.0.1

Workstation

14.x

ËùÓÐ

Critical

14.1.4

Fusion

11.x

OS X

Critical

11.0.1

Fusion

10.x

OS X

Critical

10.1.4


ÊÜCVE-2018-6982Ó°Ïì²úÆ·¼°¿ÉÌæ»»/²¹¶¡°æ±¾


²úÆ·

°æ±¾

ÔËÐÐÆ½Ì¨

ÑÏÖØË®Æ½

Ìæ»»Îª/Ó¦Óò¹¶¡

ESXi

6.7

ESXi

Important

ESXi670-201811401-BG

ESXi

6.5

ESXi

Important

ESXi650-201811301-BG

ESXi

6.0

ESXi

N/A

²»ÊÜÓ°Ïì

Workstation

ËùÓÐ

ËùÓÐ

N/A

²»ÊÜÓ°Ïì

Fusion

ËùÓÐ

OS X

N/A

²»ÊÜÓ°Ïì


Ïêϸ¸÷¸ö²úÆ·°æ±¾µÄ²¹¶¡/¿¯ÐÐ˵Ã÷£º

ESXi 6.7

https://my.vmware.com/group/vmware/patch

https://docs.vmware.com/en/VMware-vSphere/6.7/rn/esxi670-201811001.html


ESXi 6.5

https://my.vmware.com/group/vmware/patch

https://docs.vmware.com/en/VMware-vSphere/6.5/rn/esxi650-201811001.html


ESXi 6.0

https://my.vmware.com/group/vmware/patch

https://docs.vmware.com/en/VMware-vSphere/6.0/rn/esxi600-201811001.html


VMware Workstation Pro 14.1.3

https://www.vmware.com/go/downloadworkstation

https://docs.vmware.com/en/VMware-Workstation-Pro/index.html


VMware Workstation Player 14.1.3

https://www.vmware.com/go/downloadplayer

https://docs.vmware.com/en/VMware-Workstation-Player/index.html


VMware Fusion Pro / Fusion 10.1.3

https://www.vmware.com/go/downloadfusion

https://docs.vmware.com/en/VMware-Fusion/index.html


²Î¿¼Á´½Ó

https://www.vmware.com/security/advisories/VMSA-2018-0027.html