VMware | ¶à¸öÇå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-05-310x00 Îó²î¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
Îó²îÆ·¼¶ |
Ô¶³ÌʹÓà |
Ó°Ïì¹æÄ£ |
|
ESXi,Workstation,Fusion,VMRC for Mac,Horizon Client for Mac |
CVE-2020-3957 |
LPE |
¸ßΣ |
·ñ |
Fusion 11.x VMRC for Mac <= 11.x Horizon Client for Mac <= 5.x |
|
CVE-2020-3958 |
DOS |
ÖÐΣ |
ÊÇ |
ESXi 6.5,6.7 Workstation 15.x Fusion 11.x |
|
|
CVE-2020-3959 |
ML |
µÍΣ |
·ñ |
0x01 Îó²îÏêÇé
VMwareÐéÄâ»úÈí¼þ£¬£¬£¬£¬ÊÇÈ«Çò×ÀÃæµ½Êý¾ÝÖÐÐÄÐéÄ⻯½â¾ö¼Æ»®µÄÏòµ¼³§ÉÌ¡£¡£¡£¡£¡£¡£È«Çò²î±ð¹æÄ£µÄ¿Í»§ÒÀÀµVMwareÀ´½µµÍ±¾Ç®ºÍÔËÓªÓöȡ¢È·±£ÓªÒµÒ»Á¬ÐÔ¡¢ÔöÇ¿Çå¾²ÐÔ²¢×ßÏòÂÌÉ«¡£¡£¡£¡£¡£¡£
2020Äê5ÔÂ28ÈÕVMwareÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ÁËVMware ESXi£¬£¬£¬£¬Workstation£¬£¬£¬£¬Fusion£¬£¬£¬£¬VMware Remote ConsoleºÍHorizon ClientÖеĶà¸öÇå¾²Îó²î£¨CVE-2020-3957£¬£¬£¬£¬CVE-2020-3958£¬£¬£¬£¬CVE-2020-3959£©£¬£¬£¬£¬ÏêϸÐÅÏ¢ÈçÏ£º
CVE-2020-3957ÊÇVMware Fusion£¬£¬£¬£¬VMRCºÍHorizon Client²úÆ·ÖеÄÍâµØÌØÈ¨Éý¼¶Îó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚЧÀÍ¿ªÆô³ÌÐòÖеļì²éʱ¼äʹÓÃʱ¼ä£¨TOCTOU£©ÎÊÌ⣬£¬£¬£¬¹¥»÷Õß¿ÉʹÓôËÎó²î½«Í¨Ë×Óû§È¨ÏÞÌáÉýÖÁrootȨÏÞ¡£¡£¡£¡£¡£¡£
CVE-2020-3958ÊÇVMware ESXi£¬£¬£¬£¬WorkstationºÍFusion²úÆ·ÖеÄShader¹¦Ð§µÄ¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£¡£¡£ÒªÊ¹ÓôËÎó²î£¬£¬£¬£¬¹¥»÷Õß±ØÐèÄܹ»»á¼ûÆôÓÃÁË3DͼÐεÄÐéÄâ»ú£¨ÔÚESXiÉÏĬÈÏδÆôÓ㬣¬£¬£¬ÔÚWorkstationºÍFusionÉÏĬÈÏÒÑÆôÓã©¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓôËÎó²îʹÐéÄâ»úµÄvmxÀú³ÌÍ߽⣬£¬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£¡£
CVE-2020-3959ÊÇVMware ESXi£¬£¬£¬£¬WorkstationºÍFusion²úÆ·ÖеÄVMCIÄ£¿£¿£¿£¿£¿éÖеÄÄÚ´æ×ß©Îó²î¡£¡£¡£¡£¡£¡£¾ßÓÐÍâµØ·ÇÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¿ÉʹÓøÃÎó²îʹÐéÄâ»úµÄvmxÀú³ÌÍ߽⣬£¬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬Õë¶Ô²î±ðµÄ²úÆ·ºÍÎó²îÓÐÏêϸµÄÐÞ¸´°æ±¾£¬£¬£¬£¬²Î¿¼ÒÔϱí¸ñ£º
0x03 Ïà¹ØÐÂÎÅ
https://www.basquecybersecurity.eus/es/avisos/tecnicos/multiples-vulnerabilidades-productos-vmware-20200529.html
0x04 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2020-0011.html
0x05 ʱ¼äÏß
2020-05-28 VMwareÐû²¼Îó²îͨ¸æ
2020-06-01 VSRCÐû²¼Îó²îͨ¸æ


¾©¹«Íø°²±¸11010802024551ºÅ