VMware Carbon Black App ControlÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î(CVE-2021-21998)

Ðû²¼Ê±¼ä 2021-06-23

0x00 Îó²î¸ÅÊö

CVE     ID

CVE-2021-21998

ʱ      ¼ä

2021-06-17

Àà       ÐÍ

Éí·ÝÑéÖ¤ÈÆ¹ý

µÈ      ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó

µÍ

¿ÉÓÃÐÔ

µÍ

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

·ñ

 

0x01 Îó²îÏêÇé

image.png

VMware Carbon Black ? App Control ?(AppC)ÊÇÊг¡ÉϳÉÊìÇÒ¿ÉÀ©Õ¹µÄÓ¦ÓóÌÐò¿ØÖƽâ¾ö¼Æ»®Ö®Ò»¡£¡£¡£¡£Carbon Black App ControlÓÃÓÚËø¶¨Ð§ÀÍÆ÷ºÍÒªº¦ÏµÍ³£¬£¬ £¬£¬£¬£¬£¬±ÜÃâÒâÍâ¸ü¸Ä²¢È·±£Ò»Á¬×ñÊØî¿ÏµÒªÇ󡣡£¡£¡£Ê¹ÓÃÔÆÐÅÓþЧÀÍ¡¢»ùÓÚIT µÄÐÅÈÎÕ½ÂÔºÍÀ´×Ô VMware Carbon Black Cloud TM µÄ¶à¸öÍþвÇ鱨ȪԴ£¬£¬ £¬£¬£¬£¬£¬È·±£Ö»ÔÊÐíÊÜÐÅÈκÍÅú×¼µÄÈí¼þÔÚ×éÖ¯µÄÒªº¦ÏµÍ³ºÍ¶ËµãÉÏÖ´ÐС£¡£¡£¡£

2021Äê06ÔÂ22ÈÕ£¬£¬ £¬£¬£¬£¬£¬VMwareÐû²¼Ç徲ͨ¸æ£¬£¬ £¬£¬£¬£¬£¬ÐÞ¸´ÁËCarbon Black App ControlÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2021-21998)£¬£¬ £¬£¬£¬£¬£¬ÆäCVSSv3 ÆÀ·ÖΪ9.4¡£¡£¡£¡£Äܹ»ÍøÂç»á¼ûVMware Carbon Black App ControlÖÎÀíЧÀÍÆ÷µÄÔ¶³Ì¹¥»÷ÕßÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿É»ñµÃ¸Ã²úÆ·µÄÖÎÆÊÎö¼ûȨÏÞ¡£¡£¡£¡£

±ðµÄ£¬£¬ £¬£¬£¬£¬£¬VMware»¹ÐÞ¸´ÁËVMware Tools for Windows¡¢VMRC for Windows ºÍ VMware App VolumesÖеÄÒ»¸öÍâµØÌáȨÎó²î£¨CVE-2021-21999£©£¬£¬ £¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ7.8£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚÒ»¸ö²»ÊÜÏÞÖÆµÄĿ¼Öа²ÅÅÖØÃüÃûΪ "openssl.cnf "µÄ¶ñÒâÎļþÀ´Ê¹ÓôËÎó²î£¬£¬ £¬£¬£¬£¬£¬ÒÔÌáÉýȨÏÞ²¢Ö´ÐдúÂë¡£¡£¡£¡£ÏÖÔÚVMwareÒѾ­ÔÚVMware Tools for Windows 11.2.6¡¢VMRC for Windows 12.0.1¡¢App Volumes 2103ºÍ2.18.10ÖÐÐÞ¸´ÁË´ËÎó²î¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

VMware Carbon Black App Control 8.6.x£¨Windows£©< 8.6.2

VMware Carbon Black App Control 8.5.x£¨Windows£©< 8.5.8

VMware Carbon Black App Control 8.1.x¡¢8.0.x£¨Windows£©£ºÎ´×°ÖÃHotfixµÄ

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ´ËÎó²îÒѾ­ÐÞ¸´£¬£¬ £¬£¬£¬£¬£¬½¨Òéʵʱ¸üÐÂÖÁ×îа汾£º

VMware Carbon Black App Control 8.6.x£¨Windows£©8.6.2

VMware Carbon Black App Control 8.5.x£¨Windows£©8.5.8

VMware Carbon Black App Control 8.1.x¡¢8.0.x£¨Windows£©Hotfix

ÏÂÔØÁ´½Ó£º

https://www.vmware.com/security/advisories/VMSA-2021-0012.html

 

0x03 ²Î¿¼Á´½Ó

https://www.vmware.com/security/advisories/VMSA-2021-0012.html

https://www.vmware.com/security/advisories/VMSA-2021-0013.html

https://community.carbonblack.com/t5/App-Control-Documents/Critical-App-Control-Server-Patch-Announcement/ta-p/104906

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3044

 

0x04 ʱ¼äÏß

2021-06-22  VMwareÐû²¼Ç徲ͨ¸æ

2021-06-23  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png