VMware Carbon Black App ControlÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î(CVE-2021-21998)
Ðû²¼Ê±¼ä 2021-06-230x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-21998 | ʱ ¼ä | 2021-06-17 |
Àà ÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | |
¹¥»÷ÖØÆ¯ºó | µÍ | ¿ÉÓÃÐÔ | µÍ |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ·ñ |
0x01 Îó²îÏêÇé
VMware Carbon Black ? App Control ?(AppC)ÊÇÊг¡ÉϳÉÊìÇÒ¿ÉÀ©Õ¹µÄÓ¦ÓóÌÐò¿ØÖƽâ¾ö¼Æ»®Ö®Ò»¡£¡£¡£¡£Carbon Black App ControlÓÃÓÚËø¶¨Ð§ÀÍÆ÷ºÍÒªº¦ÏµÍ³£¬£¬£¬£¬£¬£¬£¬±ÜÃâÒâÍâ¸ü¸Ä²¢È·±£Ò»Á¬×ñÊØî¿ÏµÒªÇ󡣡£¡£¡£Ê¹ÓÃÔÆÐÅÓþЧÀÍ¡¢»ùÓÚIT µÄÐÅÈÎÕ½ÂÔºÍÀ´×Ô VMware Carbon Black Cloud TM µÄ¶à¸öÍþвÇ鱨ȪԴ£¬£¬£¬£¬£¬£¬£¬È·±£Ö»ÔÊÐíÊÜÐÅÈκÍÅú×¼µÄÈí¼þÔÚ×éÖ¯µÄÒªº¦ÏµÍ³ºÍ¶ËµãÉÏÖ´ÐС£¡£¡£¡£
2021Äê06ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬VMwareÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËCarbon Black App ControlÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2021-21998)£¬£¬£¬£¬£¬£¬£¬ÆäCVSSv3 ÆÀ·ÖΪ9.4¡£¡£¡£¡£Äܹ»ÍøÂç»á¼ûVMware Carbon Black App ControlÖÎÀíЧÀÍÆ÷µÄÔ¶³Ì¹¥»÷ÕßÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿É»ñµÃ¸Ã²úÆ·µÄÖÎÆÊÎö¼ûȨÏÞ¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬£¬VMware»¹ÐÞ¸´ÁËVMware Tools for Windows¡¢VMRC for Windows ºÍ VMware App VolumesÖеÄÒ»¸öÍâµØÌáȨÎó²î£¨CVE-2021-21999£©£¬£¬£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚÒ»¸ö²»ÊÜÏÞÖÆµÄĿ¼Öа²ÅÅÖØÃüÃûΪ "openssl.cnf "µÄ¶ñÒâÎļþÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬ÒÔÌáÉýȨÏÞ²¢Ö´ÐдúÂë¡£¡£¡£¡£ÏÖÔÚVMwareÒѾÔÚVMware Tools for Windows 11.2.6¡¢VMRC for Windows 12.0.1¡¢App Volumes 2103ºÍ2.18.10ÖÐÐÞ¸´ÁË´ËÎó²î¡£¡£¡£¡£
Ó°Ïì¹æÄ£
VMware Carbon Black App Control 8.6.x£¨Windows£©< 8.6.2
VMware Carbon Black App Control 8.5.x£¨Windows£©< 8.5.8
VMware Carbon Black App Control 8.1.x¡¢8.0.x£¨Windows£©£ºÎ´×°ÖÃHotfixµÄ
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ´ËÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬£¬½¨Òéʵʱ¸üÐÂÖÁ×îа汾£º
VMware Carbon Black App Control 8.6.x£¨Windows£©8.6.2
VMware Carbon Black App Control 8.5.x£¨Windows£©8.5.8
VMware Carbon Black App Control 8.1.x¡¢8.0.x£¨Windows£©Hotfix
ÏÂÔØÁ´½Ó£º
https://www.vmware.com/security/advisories/VMSA-2021-0012.html
0x03 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2021-0012.html
https://www.vmware.com/security/advisories/VMSA-2021-0013.html
https://community.carbonblack.com/t5/App-Control-Documents/Critical-App-Control-Server-Patch-Announcement/ta-p/104906
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3044
0x04 ʱ¼äÏß
2021-06-22 VMwareÐû²¼Ç徲ͨ¸æ
2021-06-23 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/