CVE-2020-3952 | VMwareÐÅϢй¶Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-04-120x00 Îó²î¸ÅÊö
CVE ID
CVE-2020-3952
ʱ ¼ä
2020-04-11
Àà ÐÍ
ÐÅϢй¶
µÈ ¼¶
ÑÏÖØ
Ó°Ïì¹æÄ£
WindowsºÍÐéÄâÉè±¹ØÁ¬ÄvCenter Server 6.7
0x01 Îó²îÏêÇé
VMware vCenter ServerÊÇÃÀ¹úÍþ¨VMware£©¹«Ë¾µÄÒ»Ì×ЧÀÍÆ÷ºÍÐéÄ⻯ÖÎÀíÈí¼þ¡£¡£¡£¸ÃÈí¼þÌṩÁËÒ»¸öÓÃÓÚÖÎÀíVMwarevSphereÇéÐεļ¯ÖÐʽƽ̨£¬£¬£¬£¬£¬£¬£¬¿É×Ô¶¯ÊµÑéºÍ½»¸¶ÐéÄâ»ù´¡¼Ü¹¹¡£¡£¡£
VMwareÐÞ¸´ÁËÒ»¸öÑÏÖØÎó²îCVE-2020-3952£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ10¡£¡£¡£¸ÃÎó²îÊÇÓëĿ¼ЧÀÍÏà¹ØµÄÐÅϢй¶Îó²î£¬£¬£¬£¬£¬£¬£¬¿É±»Ê¹ÓÃÀ´ÆÆËðvCenterServer¡£¡£¡£
WMwareÐû²¼µÄͨ¸æÖÐÌåÏÖ£ºÔÚijЩÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬×÷ΪǶÈëʽ»òÍⲿPlatform Services Controller£¨PSC£©Ò»²¿·ÖµÄVMware vCenter Server¸½´øµÄvmdirÎÞ·¨×¼È·ÊµÏÖ»á¼û¿ØÖÆ¡£¡£¡£¹¥»÷ÕßÄܹ»ÌáÈ¡µ½¸ß¶ÈÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÆÆËðvCenter Server»òÆäËûÒÀÀµvmdir¾ÙÐÐÉí·ÝÑéÖ¤µÄЧÀÍ¡£¡£¡£
¸ÃÎó²îÓ°ÏìWindowsºÍÐéÄâÉè±¹ØÁ¬ÄvCenterServer 6.7°æ±¾£¬£¬£¬£¬£¬£¬£¬²¢ÒÑͨ¹ý6.7u3f°æ±¾¾ÙÐÐÁËÐÞ²¹¡£¡£¡£VmwareÇ¿µ÷£¬£¬£¬£¬£¬£¬£¬Ö»ÓдÓÏÈǰ°æ±¾Éý¼¶×°Öú󣬣¬£¬£¬£¬£¬£¬vCenter Server²Å»áÊÜÓ°Ïì¡£¡£¡£ÈôÊÇÓû§Ö±½Ó×°ÖÃ6.7°æ±¾£¬£¬£¬£¬£¬£¬£¬Ôò²»»áÊܵ½Ó°Ïì¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
Éý¼¶vCenter Server µ½6.7u3f°æ±¾£º
https://my.vmware.com/web/vmware/details?productId=742&rPId=44888&downloadGroup=VC67U3F
0x03 Ïà¹ØÐÂÎÅ
https://securityaffairs.co/wordpress/101388/security/cve-2020-3952-vmware-vcenter-server.html
0x04 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2020-0006.html
0x05 ʱ¼äÏß
2020-04-09 Vmware¹Ù·½Ðû²¼Îó²î
2020-04-10 CVEÐû²¼¸ÃÎó²î