VMware | ¶à¸öÇå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-05-31

0x00 Îó²î¸ÅÊö



²úÆ·

CVE ID

Àà ÐÍ

Îó²îÆ·¼¶

Ô¶³ÌʹÓÃ

Ó°Ïì¹æÄ£

ESXi,Workstation,Fusion,VMRC for Mac,Horizon Client for Mac

CVE-2020-3957

LPE

¸ßΣ

·ñ

Fusion 11.x

VMRC for Mac <= 11.x

Horizon Client for Mac <= 5.x

CVE-2020-3958

DOS

ÖÐΣ

ÊÇ

ESXi 6.5,6.7

Workstation 15.x

Fusion 11.x

CVE-2020-3959

ML

µÍΣ

·ñ



0x01 Îó²îÏêÇé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


VMwareÐéÄâ»úÈí¼þ£¬£¬£¬£¬£¬ÊÇÈ«Çò×ÀÃæµ½Êý¾ÝÖÐÐÄÐéÄ⻯½â¾ö¼Æ»®µÄÏòµ¼³§ÉÌ¡£¡£¡£È«Çò²î±ð¹æÄ£µÄ¿Í»§ÒÀÀµVMwareÀ´½µµÍ±¾Ç®ºÍÔËÓªÓöȡ¢È·±£ÓªÒµÒ»Á¬ÐÔ¡¢ÔöÇ¿Çå¾²ÐÔ²¢×ßÏòÂÌÉ«¡£¡£¡£

2020Äê5ÔÂ28ÈÕVMwareÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´ÁËVMware ESXi£¬£¬£¬£¬£¬Workstation£¬£¬£¬£¬£¬Fusion£¬£¬£¬£¬£¬VMware Remote ConsoleºÍHorizon ClientÖеĶà¸öÇå¾²Îó²î£¨CVE-2020-3957£¬£¬£¬£¬£¬CVE-2020-3958£¬£¬£¬£¬£¬CVE-2020-3959£©£¬£¬£¬£¬£¬ÏêϸÐÅÏ¢ÈçÏ£º

CVE-2020-3957ÊÇVMware Fusion£¬£¬£¬£¬£¬VMRCºÍHorizon Client²úÆ·ÖеÄÍâµØÌØÈ¨Éý¼¶Îó²î¡£¡£¡£¸ÃÎó²îÔ´ÓÚЧÀÍ¿ªÆô³ÌÐòÖеļì²éʱ¼äʹÓÃʱ¼ä£¨TOCTOU£©ÎÊÌ⣬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓôËÎó²î½«Í¨Ë×Óû§È¨ÏÞÌáÉýÖÁrootȨÏÞ¡£¡£¡£

CVE-2020-3958ÊÇVMware ESXi£¬£¬£¬£¬£¬WorkstationºÍFusion²úÆ·ÖеÄShader¹¦Ð§µÄ¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£ÒªÊ¹ÓôËÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß±ØÐèÄܹ»»á¼ûÆôÓÃÁË3DͼÐεÄÐéÄâ»ú£¨ÔÚESXiÉÏĬÈÏδÆôÓ㬣¬£¬£¬£¬ÔÚWorkstationºÍFusionÉÏĬÈÏÒÑÆôÓã©¡£¡£¡£¹¥»÷Õß¿ÉʹÓôËÎó²îʹÐéÄâ»úµÄvmxÀú³ÌÍ߽⣬£¬£¬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£

CVE-2020-3959ÊÇVMware ESXi£¬£¬£¬£¬£¬WorkstationºÍFusion²úÆ·ÖеÄVMCIÄ£¿£¿£¿éÖеÄÄÚ´æ×ß©Îó²î¡£¡£¡£¾ßÓÐÍâµØ·ÇÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¿ÉʹÓøÃÎó²îʹÐéÄâ»úµÄvmxÀú³ÌÍ߽⣬£¬£¬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬Õë¶Ô²î±ðµÄ²úÆ·ºÍÎó²îÓÐÏêϸµÄÐÞ¸´°æ±¾£¬£¬£¬£¬£¬²Î¿¼ÒÔϱí¸ñ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


0x03 Ïà¹ØÐÂÎÅ


https://www.basquecybersecurity.eus/es/avisos/tecnicos/multiples-vulnerabilidades-productos-vmware-20200529.html


0x04 ²Î¿¼Á´½Ó


https://www.vmware.com/security/advisories/VMSA-2020-0011.html


0x05 ʱ¼äÏß


2020-05-28 VMwareÐû²¼Îó²îͨ¸æ

2020-06-01 VSRCÐû²¼Îó²îͨ¸æ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨