VMware Tools ÐÞ¸´ vm3dmp ºÍ ALSA µÄÁ½¸öÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-11

Îó²î±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2019-5522£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.1£¬£¬£¬¹Ù·½£º7.1

CVE±àºÅ£ºCVE-2019-5525£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.5£¬£¬£¬¹Ù·½£º8.8



Ó°Ïì°æ±¾



ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚWindows 10.xµÄVMware Tools < 10.3.10¡£¡£¡£¡£¡£¡£


ÊÊÓÃÓÚLinuxµÄVMware Workstation Pro / Player£¨Workstation£©< 15.1.0¡£¡£¡£¡£¡£¡£



Îó²î¸ÅÊö



VMware Tools ÐÞ¸´ vm3dmp Çý¶¯ºÍ ALSA µÄÁ½¸öÎó²î:


CVE-2019-5522


VMware ToolsÊÇÃÀ¹úÍþ¨VMware£©¹«Ë¾µÄÒ»Ì×VMWareÐéÄâ»ú×Ô´øµÄÔöÇ¿¹¤¾ß£¬£¬£¬ËüÊÇVMwareÌṩµÄÓÃÓÚÔöÇ¿ÐéÄâÏÔ¿¨ºÍÓ²ÅÌÐÔÄÜ¡¢ÒÔ¼°Í¬²½ÐéÄâ»úÓëÖ÷»úʱÖÓµÄÇý¶¯³ÌÐò¡£¡£¡£¡£¡£¡£


VMware Tools¸üнâ¾öÁËvm3dmpÇý¶¯³ÌÐòÖеÄÒ»¸öÔ½½ç¶ÁÈ¡Îó²î£¬£¬£¬¸ÃÇý¶¯³ÌÐòËæWindows¿Í»§»úÖеÄVMware ToolsÒ»Æð×°Öᣡ£¡£¡£¡£¡£¶Ô×°ÖÃÁËVMware ToolsµÄWindows guestÐéÄâ»ú¾ßÓзÇÖÎÆÊÎö¼ûȨÏÞµÄÍâµØ¹¥»÷Õß¿ÉÄÜ»áÔÚͳһWindows guestÅÌËã»úÉÏ×ß©ÄÚºËÐÅÏ¢»ò½¨Éè¾Ü¾øÐ§À͹¥»÷¡£¡£¡£¡£¡£¡£


CVE-2019-5525


VMware WorkstationÊÇÃÀ¹úÍþ¨VMware£©¹«Ë¾µÄÒ»Ì×ÐéÄâ»úÈí¼þ¡£¡£¡£¡£¡£¡£¸ÃÈí¼þÌṩ¿ÉÒÔͬʱÔËÐжà¸ö²î±ðµÄ²Ù×÷ϵͳµÄÐéÄâ»ú¹¦Ð§¡£¡£¡£¡£¡£¡£


VMware Workstation£¨15.1.0֮ǰµÄ15.x£©°üÀ¨¸ß¼¶LinuxÉùÒôϵͳ½á¹¹£¨ALSA£©ºó¶ËÖеÄÊͷźóÖØÓÃÎó²î¡£¡£¡£¡£¡£¡£ ÔÚ¿Í»§»úÉϾßÓÐͨË×Óû§È¨Ï޵ĶñÒâÓû§¿ÉÄܻὫ´ËÎÊÌâÓëÆäËûÎÊÌâÁ¬ÏµÊ¹Ó㬣¬£¬ÒÔÔÚ×°ÖÃÁËWorkstationµÄLinuxÖ÷»úÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£



Îó²îÑéÖ¤



ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£



ÐÞ¸´½¨Òé



ÏÖÔÚ³§ÉÌÒÑÐû²¼Ð°汾ÒÔÐÞ¸´Îó²î£¬£¬£¬½«ÊÊÓÃÓÚWindows 10.xµÄVMware Tools¸üе½10.3.10 £»£»£»£»£»½«Workstation 15.x¸üе½15.1.0¡£¡£¡£¡£¡£¡£ÏÂÔØÁ´½ÓÈçÏ£º


VMware Tools 10.3.10
Downloads and Documentation:
https://docs.vmware.com/en/VMware-Tools/index.html

https://my.vmware.com/web/vmware/details?downloadGroup=VMTOOLS10310&productId=742


VMware Workstation Pro 15.1.0
Downloads and Documentation:
https://www.vmware.com/go/downloadworkstation

https://docs.vmware.com/en/VMware-Workstation-Pro/index.html


VMware Workstation Player 15.1.0
Downloads and Documentation:
https://www.vmware.com/go/downloadplayer

https://docs.vmware.com/en/VMware-Workstation-Player/index.html



²Î¿¼Á´½Ó



https://www.vmware.com/security/advisories/VMSA-2019-0009.html