Citrix Endpoint Management¶à¸öÇå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-08-13

0x00 Îó²î¸ÅÊö


2020Äê8ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬Citrix¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÎå¸öÇå¾²Îó²î£¨CVE-2020-8208¡¢CVE-2020-8209¡¢CVE-2020-8210¡¢CVE-2020-8211¡¢CVE-2020-8212£©£¬£¬£¬£¬£¬£¬£¬ÕâЩÎó²îÓ°ÏìCitrix Endpoint Management£¨CEM£©£¨Ò²³ÆÎªXenMobileServer£©µÄ¶à¸ö°æ±¾¡£¡£¡£


0x01 Îó²îÏêÇé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



Citrix XenMobile ServerÊÇÃÀ¹úCitrix Systems¹«Ë¾µÄÒ»Ì×ÒÆ¶¯ÖÎÃ÷È·¾ö¼Æ»®¡£¡£¡£¸Ã¼Æ»®Äܹ»ÖÎÀíÒÆ¶¯×°±¸¡¢Öƶ©Òƶ¯Õ½ÂԺͺϹæÐÔ¹æÔò¡¢ÉîÈëÏàÊ¶ÒÆ¶¯Òƶ¯ÍøÂçÔËÐÐÇéÐεÈ¡£¡£¡£ÍâµØ°²ÅŵÄCitrix XenMobileÌṩÁËÒ»¸öͳһµÄ½Ó¿Ú£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÒ»¸ö¼òµ¥µÄƽ̨ÖÎÀíÔ±¹¤µĄ̈ʽ»ú£¬£¬£¬£¬£¬£¬£¬Ìõ¼Ç±¾ºÍÒÆ¶¯×°±¸£¨Æ½°åµçÄÔºÍÖÇÄÜÊÖ»ú£©¡£¡£¡£

ÕâÎå¸öÎó²îÖÐÓÐÁ½¸ö±»ÆÀΪ³¬Î£Îó²î£¨CVE-2020-8208¡¢CVE-2020-8209£©£¬£¬£¬£¬£¬£¬£¬Îó²îµ¼ÖÂδ¾­Éí·ÝÈÏÖ¤µÄ¹¥»÷Õ߿ɻñÈ¡ÖÎÀíÔ±¿ØÖÆÈ¨ÏÞ£¬£¬£¬£¬£¬£¬£¬´Ó¶ø½ÓÊÜXenMobile Servers¡£¡£¡£ÊÜÓ°ÏìµÄXenMobileServer°æ±¾ÈçÏ£º

? XenMobile Server < 10.12 RP2

? XenMobile Server < 10.11 RP4

? XenMobile Server < 10.10 RP6

? XenMobile Server < 10.9 RP5

ÆäËûÈý¸öÎó²îµÄÑÏÖØË®Æ½±»ÆÀΪÖÐΣºÍµÍΣ£¨CVE-2020-8210¡¢CVE-2020-8211¡¢CVE-2020-8212£©£¬£¬£¬£¬£¬£¬£¬Îó²îµ¼ÖÂCEMÖÎÀíÔ±¿É»á¼ûδÊÚȨµÄÐÅÏ¢¡£¡£¡£ÊÜÓ°ÏìµÄXenMobileServer°æ±¾ÈçÏ£º

? XenMobile Server < 10.12 RP3

? XenMobile Server < 10.11 RP6

? XenMobile Server < 10.10 RP6

? XenMobile Server < 10.9 RP5

Citrix½¨Òé¿Í»§Á¬Ã¦¸üÐÂXenMobile Server£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕߺÜÓпÉÄÜ»á½ô½Ó×Å×îÏÈɨÃè²éÕÒųÈõµÄЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÕâЩÎó²î¾ÙÐй¥»÷¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÕë¶Ô²î±ðµÄ°æ±¾Ðû²¼²¹¶¡£¬£¬£¬£¬£¬£¬£¬ÏêϸÄÚÈÝÈçÏ£º

? XenMobile Server 10.12 RP3: https://support.citrix.com/article/CTX277473

? XenMobile Server 10.11 RP6: https://support.citrix.com/article/CTX277698

? XenMobile Server 10.10 RP6: https://support.citrix.com/article/CTX279101

? XenMobile Server 10.9 RP5: https://support.citrix.com/article/CTX279098


0x03 Ïà¹ØÐÂÎÅ


https://www.bleepingcomputer.com/news/security/citrix-fixes-critical-bugs-allowing-takeover-of-xenmobile-servers/


0x04 ²Î¿¼Á´½Ó


https://support.citrix.com/article/CTX277457


0x05 ʱ¼äÏß


2020-08-11 Citrix¹Ù·½Ðû²¼Ç徲ͨ¸æ

2020-08-13 VSRCÐû²¼Îó²îͨ¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨