VMware View PlannerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21978£©
Ðû²¼Ê±¼ä 2021-03-030x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-21978 | ʱ ¼ä | 2021-03-03 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | VMware View Planner 4.6 |
0x01 Îó²îÏêÇé
View planner ÊÇVMware¹Ù·½ÍƳöµÄÒ»¿îÕë¶Ôview×ÀÃæµÄ²âÊÔ¹¤¾ß£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýËü¹ÀËã³öÔÚÖ¸¶¨µÄÓ¦ÓÃÇéÐÎÏ¿ÉÒÔÐû²¼¼¸¶à¸öview×ÀÃæ£¬£¬£¬£¬£¬ÆäʵÖÊÉÏÊÇÒ»¸öʹÓÃcentosµÄlinuxÐéÄâ»ú¡£¡£¡£¡£¡£¡£
2021Äê03ÔÂ02ÈÕ£¬£¬£¬£¬£¬VMware¹Ù·½Ðû²¼¸üÐÂͨ¸æ£¬£¬£¬£¬£¬ÐÞ¸´ÁËView PlannerÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21978£©£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö8.6¡£¡£¡£¡£¡£¡£
ÓÉÓÚ²»×¼È·µÄÊäÈëÑéÖ¤ºÍȱ·¦ÊÚȨ£¬£¬£¬£¬£¬¿ÉÒÔÔÚlogupload webÓ¦ÓóÌÐòÖÐÉÏ´«í§ÒâÎļþ¡£¡£¡£¡£¡£¡£Äܹ»»á¼ûView Planner HarnessµÄ¹¥»÷Õß¿ÉÒÔÉÏ´«²¢Ö´ÐжñÒâÎļþ£¬£¬£¬£¬£¬×îÖÕÔÚloguploadÈÝÆ÷ÄÚÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚVMwareÒѾÐû²¼ÁËÐÞ¸´³ÌÐò£¬£¬£¬£¬£¬½¨ÒéʵʱװÖÃView Planner 4.6 Security Patch 1¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://my.vmware.com/web/vmware/downloads/details?downloadGroup=VIEW-PLAN-460&productId=1067&rPId=53394
0x03 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2021-0003.html
https://docs.vmware.com/en/VMware-View-Planner/4.6/rn/VMware-View-Planner-46-Release-Notes.html#patch-releases-2
https://cve.mitre.org/cgi-bin/cvename.cgi?name=VE-2021-21978
0x04 ʱ¼äÏß
2021-03-02 VmwareÐû²¼Ç徲ͨ¸æ
2021-03-03 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/