VMware vCenter ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21985£©

Ðû²¼Ê±¼ä 2021-05-26

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2021-21985

ʱ   ¼ä

2021-05-26

Àà   ÐÍ

RCE

µÈ   ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

·ñ


0x01
Îó²îÏêÇé

image.png

 

vCenter ServerÊÇVMware¹«Ë¾µÄÒ»ÖÖЧÀÍÆ÷ÖÎÃ÷È·¾ö¼Æ»®£¬£¬£¬¿É×ÊÖúITÖÎÀíԱͨ¹ýµ¥¸ö¿ØÖÆÌ¨ÖÎÀíÆóÒµÇéÐÎÖеÄÐéÄâ»úºÍÐéÄ⻯Ö÷»ú¡£¡£¡£¡£

2021Äê05ÔÂ25ÈÕ£¬£¬£¬VMwareÐû²¼ÁËvCenter ServerÇå¾²¸üУ¬£¬£¬ÐÞ¸´ÁËvSphere ClientÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21985£©ºÍÒ»¸öÉí·ÝÑéÖ¤Îó²î£¨CVE-2021-21986£©£¬£¬£¬ÆäCVSSv3»ù±¾µÃ·Ö»®·ÖΪ9.8ºÍ6.5¡£¡£¡£¡£

vCenter ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21985£©

¸ÃÎó²î±£´æÓÚvSphere Client£¨HTML5£©ÖУ¬£¬£¬ÓÉÓÚvCenter ServerÖÐĬÈÏÆôÓõÄVirtual SAN Health Check²å¼þȱ·¦ÊäÈëÑéÖ¤£¬£¬£¬ÓµÓÐ443¶Ë¿ÚÍøÂç»á¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚ³ÐÔØvCenter ServerµÄ²Ù×÷ϵͳÉÏÔ¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£

ÐèÒª×¢ÖØµÄÊÇ£¬£¬£¬Virtual SAN Health Check²å¼þÔÚËùÓÐvCenter ServerÖж¼Ä¬ÈÏÆôÓ㬣¬£¬ÈκÎÄܹ»Í¨¹ýÍøÂç»á¼ûvCenter ServerµÄδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¶¼¿ÉÒÔʹÓÃÕâ¸öÎó²î£¬£¬£¬¶øÎÞÂÛÊÇ·ñʹÓÃvSAN£¬£¬£¬²¢ÇÒ¸ÃÎó²îÎÞÐèÓû§½»»¥¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£

 

vCenter ServerÉí·ÝÑéÖ¤Îó²î£¨CVE-2021-21986£©

¸ÃÎó²î±£´æÓÚvSphere Client (HTML5)µÄVirtual SAN Health Check¡¢Site Recovery¡¢vSphere Lifecycle ManagerºÍVMware Cloud Director Availability²å¼þµÄvSphereÈÏÖ¤»úÖÆÖУ¬£¬£¬¾ßÓÐ vCenter Server É쵀 443 ¶Ë¿ÚÍøÂç»á¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔʹÓôËÎó²îÖ´ÐÐÊÜÓ°Ïì²å¼þËùÔÊÐíµÄ²Ù×÷£¬£¬£¬¶øÎÞÐè¾ÙÐÐÉí·ÝÑéÖ¤¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

vCenter Server 7.0

vCenter Server 6.7

vCenter Server 6.5

Cloud Foundation (vCenter Server) 4.x

Cloud Foundation (vCenter Server) 3.x

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚVMwareÒѾ­ÐÞ¸´ÁËÕâЩÎó²î£¬£¬£¬½¨Ò龡¿ìÉý¼¶µ½ÒÔÏÂÐÞ¸´°æ±¾»òʵʱӦÓûº½â²½·¥£º

vCenter Server 7.0 U2b

vCenter Server 6.7 U3n

vCenter Server 6.5 U3p

Cloud Foundation (vCenter Server) 4.2.1

Cloud Foundation (vCenter Server) 3.10.2.1

 

ÏÂÔØÁ´½Ó£º

https://www.vmware.com/security/advisories/VMSA-2021-0010.html

 

0x03 ²Î¿¼Á´½Ó

https://docs.vmware.com/en/VMware-vSphere/7.0/rn/vsphere-vcenter-server-70u2b-release-notes.html

https://kb.vmware.com/s/article/83829

https://core.vmware.com/resource/vmsa-2021-0010-faq

https://www.bleepingcomputer.com/news/security/vmware-warns-of-critical-bug-affecting-all-vcenter-server-installs/

 

0x04 ʱ¼äÏß

2021-05-25  VMwareÐû²¼Ç徲ͨ¸æ

2021-05-26  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png