VMware | ¶à¸öÇå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-05-310x00 Îó²î¸ÅÊö
²úÆ· |
CVE ID |
Àà ÐÍ |
Îó²îÆ·¼¶ |
Ô¶³ÌʹÓà |
Ó°Ïì¹æÄ£ |
ESXi,Workstation,Fusion,VMRC for Mac,Horizon Client for Mac |
CVE-2020-3957 |
LPE |
¸ßΣ |
·ñ |
Fusion 11.x VMRC for Mac <= 11.x Horizon Client for Mac <= 5.x |
CVE-2020-3958 |
DOS |
ÖÐΣ |
ÊÇ |
ESXi 6.5,6.7 Workstation 15.x Fusion 11.x |
|
CVE-2020-3959 |
ML |
µÍΣ |
·ñ |
0x01 Îó²îÏêÇé
VMwareÐéÄâ»úÈí¼þ£¬£¬£¬£¬£¬ÊÇÈ«Çò×ÀÃæµ½Êý¾ÝÖÐÐÄÐéÄ⻯½â¾ö¼Æ»®µÄÏòµ¼³§ÉÌ¡£¡£¡£È«Çò²î±ð¹æÄ£µÄ¿Í»§ÒÀÀµVMwareÀ´½µµÍ±¾Ç®ºÍÔËÓªÓöȡ¢È·±£ÓªÒµÒ»Á¬ÐÔ¡¢ÔöÇ¿Çå¾²ÐÔ²¢×ßÏòÂÌÉ«¡£¡£¡£
2020Äê5ÔÂ28ÈÕVMwareÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´ÁËVMware ESXi£¬£¬£¬£¬£¬Workstation£¬£¬£¬£¬£¬Fusion£¬£¬£¬£¬£¬VMware Remote ConsoleºÍHorizon ClientÖеĶà¸öÇå¾²Îó²î£¨CVE-2020-3957£¬£¬£¬£¬£¬CVE-2020-3958£¬£¬£¬£¬£¬CVE-2020-3959£©£¬£¬£¬£¬£¬ÏêϸÐÅÏ¢ÈçÏ£º
CVE-2020-3957ÊÇVMware Fusion£¬£¬£¬£¬£¬VMRCºÍHorizon Client²úÆ·ÖеÄÍâµØÌØÈ¨Éý¼¶Îó²î¡£¡£¡£¸ÃÎó²îÔ´ÓÚЧÀÍ¿ªÆô³ÌÐòÖеļì²éʱ¼äʹÓÃʱ¼ä£¨TOCTOU£©ÎÊÌ⣬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓôËÎó²î½«Í¨Ë×Óû§È¨ÏÞÌáÉýÖÁrootȨÏÞ¡£¡£¡£
CVE-2020-3958ÊÇVMware ESXi£¬£¬£¬£¬£¬WorkstationºÍFusion²úÆ·ÖеÄShader¹¦Ð§µÄ¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£ÒªÊ¹ÓôËÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß±ØÐèÄܹ»»á¼ûÆôÓÃÁË3DͼÐεÄÐéÄâ»ú£¨ÔÚESXiÉÏĬÈÏδÆôÓ㬣¬£¬£¬£¬ÔÚWorkstationºÍFusionÉÏĬÈÏÒÑÆôÓã©¡£¡£¡£¹¥»÷Õß¿ÉʹÓôËÎó²îʹÐéÄâ»úµÄvmxÀú³ÌÍ߽⣬£¬£¬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£
CVE-2020-3959ÊÇVMware ESXi£¬£¬£¬£¬£¬WorkstationºÍFusion²úÆ·ÖеÄVMCIÄ£¿£¿£¿éÖеÄÄÚ´æ×ß©Îó²î¡£¡£¡£¾ßÓÐÍâµØ·ÇÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¿ÉʹÓøÃÎó²îʹÐéÄâ»úµÄvmxÀú³ÌÍ߽⣬£¬£¬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬Õë¶Ô²î±ðµÄ²úÆ·ºÍÎó²îÓÐÏêϸµÄÐÞ¸´°æ±¾£¬£¬£¬£¬£¬²Î¿¼ÒÔϱí¸ñ£º
0x03 Ïà¹ØÐÂÎÅ
https://www.basquecybersecurity.eus/es/avisos/tecnicos/multiples-vulnerabilidades-productos-vmware-20200529.html
0x04 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2020-0011.html
0x05 ʱ¼äÏß
2020-05-28 VMwareÐû²¼Îó²îͨ¸æ
2020-06-01 VSRCÐû²¼Îó²îͨ¸æ