VMware vSphere ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21972£©
Ðû²¼Ê±¼ä 2021-02-240x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-21972 | ʱ ¼ä | 2021-02-24 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ |
0x01 Îó²îÏêÇé
VMware vCenter ServerÊǸ߼¶Ð§ÀÍÆ÷ÖÎÀíÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÆäÌṩÁËÒ»¸ö¼¯ÖÐʽƽ̨À´¿ØÖƵÄVMware vSphere ÇéÐΣ¬£¬£¬£¬£¬£¬£¬Ê¹Óû§Äܹ»ÔÚÕû¸ö»ìÏýÔÆÖÐ×Ô¶¯°²ÅŲ¢½»¸¶ÐéÄâ»ù´¡¼Ü¹¹¡£¡£¡£¡£¡£
2021Äê02ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬£¬VmwareÐû²¼ÁËvCenter ServerÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËvSphere Client (HTML5) ÔÚvCenter Server²å¼þvRealize Operations£¨vROps£©ÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21972£©£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£Äܹ»»á¼ûÍøÂç¶Ë¿Ú443µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÔÚÍйÜvCenter ServerµÄ²Ù×÷ϵͳÉÏÒÔ²»ÊÜÏÞÖÆµÄȨÏÞÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÊÜÓ°ÏìµÄ²å¼þ±£´æÓÚËùÓÐĬÈÏ×°ÖÃÖУ¬£¬£¬£¬£¬£¬£¬¼øÓÚ´ËÎó²îµÄÑÏÖØÐÔ£¬£¬£¬£¬£¬£¬£¬VMwareÇ¿ÁÒ½¨ÒéÓû§¾¡¿ìÉý¼¶¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬£¬VMware»¹ÐÞ¸´ÁËVMware ESXiÖÐÒ»¸öÖ÷ÒªµÄ¶ÑÒç³öÎó²î£¨CVE-2021-21974£©£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö8.8¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
2020Äê4Ô£¬£¬£¬£¬£¬£¬£¬VMware½â¾öÁËÁíÒ»¸öÑÏÖØµÄvCenter ServerÎó²î£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÄÜʹ¹¥»÷ÕßÄܹ»»á¼ûÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬²¢¿ÉÄÜ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
vCenter Server 6.5
vCenter Server 6.7
vCenter Server 7.0
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ¸ÃÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬£¬½¨Òé²Î¿¼Ï±íʵʱÉý¼¶¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾ | ÐÞ¸´°æ±¾ | ²Î¿¼Á´½Ó£¨ÔÝʱÐÞ¸´£© |
vCenter Server 6.5 | 6.5 U3n | https://kb.vmware.com/s/article/82374 |
vCenter Server 6.7 | 6.7 U3l | |
vCenter Server 7.0 | 7.0 U1c |
ÏÂÔØÁ´½Ó£º
vCenter Server 6.5 U3n
https://docs.vmware.com/en/VMware-vSphere/6.5/rn/vsphere-vcenter-server-65u3n-release-notes.html
vCenter Server 6.7 U3l
https://docs.vmware.com/en/VMware-vSphere/6.7/rn/vsphere-vcenter-server-67u3l-release-notes.html
vCenter Server 7.0 U1c
https://docs.vmware.com/en/VMware-vSphere/7.0/rn/vsphere-vcenter-server-70u1c-release-notes.html
0x03 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2021-0002.html
https://www.bleepingcomputer.com/news/security/vmware-fixes-critical-rce-bug-in-all-default-vcenter-installs/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21972
0x04 ʱ¼äÏß
2021-02-23 VmwareÐû²¼Çå¾²¸üÐÂ
2021-02-24 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/