CVE-2020-3960 | VMware¶à¸ö²úÆ·ÐÅϢй¶Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-06-110x00 Îó²î¸ÅÊö
²úÆ· |
CVE ID |
Àà ÐÍ |
Îó²îÆ·¼¶ |
Ô¶³ÌʹÓà |
Ó°Ïì¹æÄ£ |
VMware vSphere ESXi (ESXi) |
CVE-2020-3960 |
ROB |
ÑÏÖØ |
ÊÇ |
ESXi 6.5¡¢6.7 |
VMware Workstation Pro / Player (Workstation) |
CVE-2020-3960 |
ROB |
ÑÏÖØ |
ÊÇ |
Workstation 15.x |
VMware Fusion Pro / Fusion (Fusion) |
CVE-2020-3960 |
ROB |
ÑÏÖØ |
ÊÇ |
Fusion 11.x |
0x01 Îó²îÏêÇé
VMwareÐéÄâ»úÈí¼þ£¬£¬£¬ÊÇÈ«Çò×ÀÃæµ½Êý¾ÝÖÐÐÄÐéÄ⻯½â¾ö¼Æ»®µÄÏòµ¼³§ÉÌ¡£¡£¡£¡£¡£¡£¡£È«Çò²î±ð¹æÄ£µÄ¿Í»§ÒÀÀµVMwareÀ´½µµÍ±¾Ç®ºÍÔËÓªÓöȡ¢È·±£ÓªÒµÒ»Á¬ÐÔ¡¢ÔöÇ¿Çå¾²ÐÔ²¢×ßÏòÂÌÉ«¡£¡£¡£¡£¡£¡£¡£
2020Äê6ÔÂ9ÈÕVMwareÐû²¼Çå¾²¸üУ¬£¬£¬ÐÞ¸´ÁËVMware ESXi¡¢WorkstationºÍFusion²úÆ·ÖеĶà¸öÇå¾²Îó²î£¬£¬£¬ÏêϸÐÅÏ¢ÈçÏ£º
Vmware ESXi¡¢WorkstationºÍFusion²úÆ·ÖеÄNVMe¹¦Ð§ÖаüÀ¨Ô½½ç¶ÁÈ¡Îó²î£¨CVE-2020-3960£©¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÒÔ·ÇÖÎÀíÔ±Éí·Ý»á¼ûÐéÄâ»ú²¢´ÓÄÚ´æÖжÁÈ¡ÌØÈ¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
NVMe£¨Nonvolatile Memory Express£¬£¬£¬·ÇÒ×ʧÐÔÄÚ´æ±ê×¼£©ÊÇÒ»ÖÖÉÁ´æºÍÏÂÒ»´ú¹Ì̬Çý¶¯Æ÷ (SSD) µÄȫд洢»á¼ûºÍ´«ÊäÐÒ飬£¬£¬¿ÉΪËùÓÐÀàÐÍµÄÆóÒµÊÂÇé¸ºÔØÌṩ×î¸ßµÄÍÌÍÂÁ¿ºÍ×î¿ìµÄÏìÓ¦ËÙÂÊ¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
VMwareÒѾÐû²¼ÉÏÊöÎó²îµÄ²¹¶¡£¬£¬£¬¿ÉÊÇûÓÐÌṩ½â¾öÒªÁì¡£¡£¡£¡£¡£¡£¡£
ESXi 6.7²¹¶¡³ÌÐòESXi670-202006401-SG
https://my.vmware.com/group/vmware/patch
https://docs.vmware.com/en/VMware-vSphere/6.7/rn/ESXi670-202006401-SG.html
ESXi 6.5²¹¶¡³ÌÐòESXi650-202005401-SG
https://my.vmware.com/group/vmware/patch
https://docs.vmware.com/en/VMware-vSphere/6.5/rn/ESXi650-202005401-SG.html
VMware Workstation Pro 15.5.5
https://www.vmware.com/go/downloadworkstation
https://docs.vmware.com/cn/VMware-Workstation-Pro/index.html
VMware Fusion 11.5.5
https://www.vmware.com/go/downloadfusion
https://docs.vmware.com/cn/VMware-Fusion/index.html
0x03 Ïà¹ØÐÂÎÅ
https://securityaffairs.co/wordpress/104579/security/vmware-products-flaw.html?utm_source=rss&utm_medium=rss&utm_campaign=vmware-products-flaw
0x04 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2020-0012.html
0x05 ʱ¼äÏß
2020-06-09 VMwareÐû²¼Îó²îͨ¸æ
2020-06-11 VSRCÐû²¼Îó²îͨ¸æ
