¡¾Îó²îͨ¸æ¡¿VMware vCenter Serverí§ÒâÎļþ¶ÁÈ¡Îó²î (CVE-2021-21980)

Ðû²¼Ê±¼ä 2021-11-25

 

0x00 Îó²î¸ÅÊö

CVE     ID

CVE-2021-21980

ʱ      ¼ä

2021-11-23

Àà      ÐÍ

í§ÒâÎļþ¶ÁÈ¡

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó

µÍ

¿ÉÓÃÐÔ

ÎÞ

Óû§½»»¥

 ÎÞ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP


ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

image.png

2021Äê11ÔÂ23ÈÕ£¬£¬£¬VMwareÐû²¼vCenter Server Çå¾²¸üУ¬£¬£¬ÐÞ¸´ÁËvSphere Web Client ÖеÄÒ»¸öí§ÒâÎļþ¶ÁÈ¡Îó²î (CVE-2021-21980)£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.5¡£¡£¡£¡£¡£¡£

¸ÃÎó²î±£´æÓÚvSphere Web Client£¨FLEX/Flash£©ÖУ¬£¬£¬Äܹ»»á¼ûvCenter Server É쵀 443 ¶Ë¿ÚµÄ¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚδÊÚȨµÄÇéÐÎ϶ÁÈ¡í§ÒâÎļþ²¢»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£

±ðµÄ£¬£¬£¬VMware»¹ÐÞ¸´ÁËvSphere Web Client ÖÐµÄ Ò»¸öSSRF Îó²î (CVE-2021-22049)£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ6.5¡£¡£¡£¡£¡£¡£Äܹ»»á¼û vCenter Server É쵀 443 ¶Ë¿ÚµÄ¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²î»á¼ûvCenter Server ÍⲿµÄ URL ÇëÇó»ò»á¼ûÄÚ²¿Ð§ÀÍ¡£¡£¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

vCenter Server 6.7

vCenter Server 6.5

Cloud Foundation (vCenter Server) 3.x

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÕâЩÎó²îÒѾ­ÐÞ¸´£¬£¬£¬½¨ÒéʵʱÉý¼¶¸üе½ÒÔϰ汾£º

vCenter Server 6.7 U3p

ÏÂÔØÁ´½Ó£º

https://customerconnect.vmware.com/en/downloads/details?downloadGroup=VC67U3P&productId=742&rPId=78421

vCenter Server 6.5 U3r

ÏÂÔØÁ´½Ó£º

https://customerconnect.vmware.com/downloads/details?downloadGroup=VC65U3R&productId=614&rPId=74057

×¢ÖØ£ºvCenter Server vSphere Web Client (FLEX/Flash)ÔÚvCenter Server 7.xÖв»¿ÉÓ㬣¬£¬Òò´ËvCenter Server 7.xÖв»±£´æÕâЩÎó²î¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬VMwareÔÝδÐû²¼Cloud Foundation (vCenter Server) 3.xµÄ²¹¶¡¡£¡£¡£¡£¡£¡£


0x03 ²Î¿¼Á´½Ó

https://www.vmware.com/security/advisories/VMSA-2021-0027.html

https://docs.vmware.com/en/VMware-vSphere/6.7/rn/vsphere-vcenter-server-67u3p-release-notes.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21980

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-11-25

Ê×´ÎÐû²¼

 

0x05 ¹ØÓÚÍòÀû¹ú¼Ê¹ÙÍø

ÍòÀû¹ú¼Ê¹ÙÍø¼ò½é

ÍòÀû¹ú¼Ê¹ÙÍø¹«Ë¾½¨ÉèÓÚ1996Ä꣬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·ºÍÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ£»£»£»£»£»²¢ÔÚ»ª±±¡¢»ª¶«¡¢Î÷ÄϺͻªÄϽṹËÄ´óÑз¢ÖÐÐÄ£¬£¬£¬»®·ÖΪ±±¾©Ñз¢×ܲ¿¡¢ÉϺ£Ñз¢ÖÐÐÄ¡¢³É¶¼Ñз¢ÖÐÐĺ͹ãÖÝÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£¡£

¶àÄêÀ´£¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£


¹ØÓÚÍòÀû¹ú¼Ê¹ÙÍø

ÍòÀû¹ú¼Ê¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png