¡¾Îó²îͨ¸æ¡¿VMware vCenter ServerÈÏÖ¤ÏÂÁîÖ´ÐÐÎó²î(CVE-2025-41225)

Ðû²¼Ê±¼ä 2025-05-22

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

VMware vCenter ServerÈÏÖ¤ÏÂÁîÖ´ÐÐÎó²î

CVE   ID

CVE-2025-41225

Îó²îÀàÐÍ

ÏÂÁîÖ´ÐÐ

·¢Ã÷ʱ¼ä

2025-05-22

Îó²îÆÀ·Ö

8.8

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍâµØ

ËùÐèȨÏÞ

µÍ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


vCenterÊÇVMwareÌṩµÄ¼¯ÖÐÖÎÀíÆ½Ì¨£¬£¬ £¬£¬£¬ÓÃÓÚÖÎÀíVMware vSphereÇéÐÎÖеÄÐéÄ⻯×ÊÔ´¡£¡£¡£¡£¡£¡£¡£ËüÔÊÐíÖÎÀíÔ±¶ÔÐéÄâ»ú¡¢Ö÷»ú¡¢´æ´¢ºÍÍøÂç¾ÙÐÐͳһÖÎÀíºÍ¼à¿Ø¡£¡£¡£¡£¡£¡£¡£vCenterÌṩ¹¦Ð§ÈçÐéÄâ»ú°²ÅÅ¡¢×Ô¶¯»¯ÖÎÀí¡¢×ÊÔ´ÓÅ»¯ºÍ¸ß¿ÉÓÃÐÔ£¬£¬ £¬£¬£¬×ÊÖúÆóÒµÌá¸ßÐéÄ⻯ÇéÐεÄЧÂʺÍÎÞаÐÔ¡£¡£¡£¡£¡£¡£¡£vCenterÊÇ´ó¹æÄ£Êý¾ÝÖÐÐĺÍÔÆÇéÐÎÖв»¿É»òȱµÄÖÎÀí¹¤¾ß£¬£¬ £¬£¬£¬Ö§³Ö¼¯ÈºÖÎÀí¡¢¸ºÔØÆ½ºâºÍ¹ÊÕϻָ´µÈ¸ß¼¶ÌØÕ÷¡£¡£¡£¡£¡£¡£¡£


2025Äê5ÔÂ22ÈÕ£¬£¬ £¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½VMwareÐû²¼µÄÇ徲ͨ¸æ£¬£¬ £¬£¬£¬Ö¸³öVMware vCenter±£´æÈÏÖ¤ÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔھ߱¸½¨Éè»òÐ޸ľ¯±¨ÒÔ¼°Ö´Ðо籾²Ù×÷ȨÏÞʱ£¬£¬ £¬£¬£¬¿ÉÄÜʹÓøÃÎó²îÔÚvCenter ServerÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£Èô¸ÃÎó²î±»ÀÖ³ÉʹÓ㬣¬ £¬£¬£¬¹¥»÷Õß¿ÉÄÜ»ñµÃϵͳ¿ØÖÆÈ¨ÏÞ»òÀÄÓÃϵͳ£¬£¬ £¬£¬£¬´øÀ´ÑÏÖØµÄÇ徲Σº¦¡£¡£¡£¡£¡£¡£¡£Îó²î¼¶±ð¸ßΣ£¬£¬ £¬£¬£¬Îó²îÆÀ·Ö8.8·Ö¡£¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


vCenter Server 8.0 < 8.0 U3e
vCenter Server 7.0 < 7.0 U3v
VMware Cloud Foundation (vCenter) = 5.x
VMware Cloud Foundation (vCenter) = 4.5.x
VMware Telco Cloud Platform (vCenter) 5.x/4.x/3.x/2.x < 8.0 U3e
VMware Telco Cloud Infrastructure (vCenter) 3.x < 8.0 U3e
VMware Telco Cloud Infrastructure (vCenter) 2.x < 7.0 U3v


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬ £¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶¡£¡£¡£¡£¡£¡£¡£
vCenter Server 8.0 >= 8.0 U3e
vCenter Server 7.0 >= 7.0 U3v
VMware Telco Cloud Platform (vCenter) 5.x/4.x/3.x/2.x >= 8.0 U3e
VMware Telco Cloud Infrastructure (vCenter) 3.x >= 8.0 U3e
VMware Telco Cloud Infrastructure (vCenter) 2.x >= 7.0 U3v


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬ £¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬ £¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬ £¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬ £¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬ £¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬ £¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬ £¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬ £¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬ £¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25717