VMware vSphere ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21972£©

Ðû²¼Ê±¼ä 2021-02-24

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2021-21972

ʱ  ¼ä

2021-02-24

Àà  ÐÍ

RCE

µÈ  ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


 

0x01 Îó²îÏêÇé

image.png

 

VMware vCenter ServerÊǸ߼¶Ð§ÀÍÆ÷ÖÎÀíÈí¼þ£¬£¬ £¬£¬£¬£¬£¬ÆäÌṩÁËÒ»¸ö¼¯ÖÐʽƽ̨À´¿ØÖƵÄVMware vSphere ÇéÐΣ¬£¬ £¬£¬£¬£¬£¬Ê¹Óû§Äܹ»ÔÚÕû¸ö»ìÏýÔÆÖÐ×Ô¶¯°²ÅŲ¢½»¸¶ÐéÄâ»ù´¡¼Ü¹¹ ¡£¡£¡£¡£¡£

2021Äê02ÔÂ23ÈÕ£¬£¬ £¬£¬£¬£¬£¬VmwareÐû²¼ÁËvCenter ServerÇå¾²¸üУ¬£¬ £¬£¬£¬£¬£¬ÐÞ¸´ÁËvSphere Client (HTML5) ÔÚvCenter Server²å¼þvRealize Operations£¨vROps£©ÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21972£©£¬£¬ £¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8 ¡£¡£¡£¡£¡£Äܹ»»á¼ûÍøÂç¶Ë¿Ú443µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÔÚÍйÜvCenter ServerµÄ²Ù×÷ϵͳÉÏÒÔ²»ÊÜÏÞÖÆµÄȨÏÞÖ´ÐÐÏÂÁî ¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚÊÜÓ°ÏìµÄ²å¼þ±£´æÓÚËùÓÐĬÈÏ×°ÖÃÖУ¬£¬ £¬£¬£¬£¬£¬¼øÓÚ´ËÎó²îµÄÑÏÖØÐÔ£¬£¬ £¬£¬£¬£¬£¬VMwareÇ¿ÁÒ½¨ÒéÓû§¾¡¿ìÉý¼¶ ¡£¡£¡£¡£¡£

±ðµÄ£¬£¬ £¬£¬£¬£¬£¬VMware»¹ÐÞ¸´ÁËVMware ESXiÖÐÒ»¸öÖ÷ÒªµÄ¶ÑÒç³öÎó²î£¨CVE-2021-21974£©£¬£¬ £¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö8.8 ¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÔ¶³ÌÖ´ÐÐí§Òâ´úÂë ¡£¡£¡£¡£¡£

2020Äê4Ô£¬£¬ £¬£¬£¬£¬£¬VMware½â¾öÁËÁíÒ»¸öÑÏÖØµÄvCenter ServerÎó²î£¬£¬ £¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÄÜʹ¹¥»÷ÕßÄܹ»»á¼ûÃô¸ÐÐÅÏ¢£¬£¬ £¬£¬£¬£¬£¬²¢¿ÉÄÜ¿ØÖÆÊÜÓ°ÏìµÄϵͳ ¡£¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

vCenter Server 6.5

vCenter Server 6.7

vCenter Server 7.0

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ¸ÃÎó²îÒѾ­ÐÞ¸´£¬£¬ £¬£¬£¬£¬£¬½¨Òé²Î¿¼Ï±íʵʱÉý¼¶ ¡£¡£¡£¡£¡£

Ó°Ïì°æ±¾

ÐÞ¸´°æ±¾

²Î¿¼Á´½Ó£¨ÔÝʱÐÞ¸´£©

vCenter Server 6.5

6.5 U3n

https://kb.vmware.com/s/article/82374

vCenter Server 6.7

6.7 U3l

vCenter Server 7.0

7.0 U1c

 

ÏÂÔØÁ´½Ó£º

vCenter Server 6.5 U3n

https://docs.vmware.com/en/VMware-vSphere/6.5/rn/vsphere-vcenter-server-65u3n-release-notes.html

 

vCenter Server 6.7 U3l

https://docs.vmware.com/en/VMware-vSphere/6.7/rn/vsphere-vcenter-server-67u3l-release-notes.html

 

vCenter Server 7.0 U1c

https://docs.vmware.com/en/VMware-vSphere/7.0/rn/vsphere-vcenter-server-70u1c-release-notes.html

 

0x03 ²Î¿¼Á´½Ó

https://www.vmware.com/security/advisories/VMSA-2021-0002.html

https://www.bleepingcomputer.com/news/security/vmware-fixes-critical-rce-bug-in-all-default-vcenter-installs/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21972

 

0x04 ʱ¼äÏß

2021-02-23  VmwareÐû²¼Çå¾²¸üÐÂ

2021-02-24  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png