VMware | ¶à¸öÇå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-05-31

0x00 Îó²î¸ÅÊö



²úÆ·

CVE ID

Àà ÐÍ

Îó²îÆ·¼¶

Ô¶³ÌʹÓÃ

Ó°Ïì¹æÄ£

ESXi,Workstation,Fusion,VMRC for Mac,Horizon Client for Mac

CVE-2020-3957

LPE

¸ßΣ

·ñ

Fusion 11.x

VMRC for Mac <= 11.x

Horizon Client for Mac <= 5.x

CVE-2020-3958

DOS

ÖÐΣ

ÊÇ

ESXi 6.5,6.7

Workstation 15.x

Fusion 11.x

CVE-2020-3959

ML

µÍΣ

·ñ



0x01 Îó²îÏêÇé


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


VMwareÐéÄâ»úÈí¼þ£¬£¬£¬ÊÇÈ«Çò×ÀÃæµ½Êý¾ÝÖÐÐÄÐéÄ⻯½â¾ö¼Æ»®µÄÏòµ¼³§ÉÌ¡£¡£¡£¡£¡£¡£¡£È«Çò²î±ð¹æÄ£µÄ¿Í»§ÒÀÀµVMwareÀ´½µµÍ±¾Ç®ºÍÔËÓªÓöȡ¢È·±£ÓªÒµÒ»Á¬ÐÔ¡¢ÔöÇ¿Çå¾²ÐÔ²¢×ßÏòÂÌÉ«¡£¡£¡£¡£¡£¡£¡£

2020Äê5ÔÂ28ÈÕVMwareÐû²¼Çå¾²¸üУ¬£¬£¬ÐÞ¸´ÁËVMware ESXi£¬£¬£¬Workstation£¬£¬£¬Fusion£¬£¬£¬VMware Remote ConsoleºÍHorizon ClientÖеĶà¸öÇå¾²Îó²î£¨CVE-2020-3957£¬£¬£¬CVE-2020-3958£¬£¬£¬CVE-2020-3959£©£¬£¬£¬ÏêϸÐÅÏ¢ÈçÏ£º

CVE-2020-3957ÊÇVMware Fusion£¬£¬£¬VMRCºÍHorizon Client²úÆ·ÖеÄÍâµØÌØÈ¨Éý¼¶Îó²î¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚЧÀÍ¿ªÆô³ÌÐòÖеļì²éʱ¼äʹÓÃʱ¼ä£¨TOCTOU£©ÎÊÌ⣬£¬£¬¹¥»÷Õß¿ÉʹÓôËÎó²î½«Í¨Ë×Óû§È¨ÏÞÌáÉýÖÁrootȨÏÞ¡£¡£¡£¡£¡£¡£¡£

CVE-2020-3958ÊÇVMware ESXi£¬£¬£¬WorkstationºÍFusion²úÆ·ÖеÄShader¹¦Ð§µÄ¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£¡£¡£¡£ÒªÊ¹ÓôËÎó²î£¬£¬£¬¹¥»÷Õß±ØÐèÄܹ»»á¼ûÆôÓÃÁË3DͼÐεÄÐéÄâ»ú£¨ÔÚESXiÉÏĬÈÏδÆôÓ㬣¬£¬ÔÚWorkstationºÍFusionÉÏĬÈÏÒÑÆôÓã©¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓôËÎó²îʹÐéÄâ»úµÄvmxÀú³ÌÍ߽⣬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£¡£¡£

CVE-2020-3959ÊÇVMware ESXi£¬£¬£¬WorkstationºÍFusion²úÆ·ÖеÄVMCIÄ£¿£¿£¿£¿éÖеÄÄÚ´æ×ß©Îó²î¡£¡£¡£¡£¡£¡£¡£¾ßÓÐÍâµØ·ÇÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¿ÉʹÓøÃÎó²îʹÐéÄâ»úµÄvmxÀú³ÌÍ߽⣬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬Õë¶Ô²î±ðµÄ²úÆ·ºÍÎó²îÓÐÏêϸµÄÐÞ¸´°æ±¾£¬£¬£¬²Î¿¼ÒÔϱí¸ñ£º


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


0x03 Ïà¹ØÐÂÎÅ


https://www.basquecybersecurity.eus/es/avisos/tecnicos/multiples-vulnerabilidades-productos-vmware-20200529.html


0x04 ²Î¿¼Á´½Ó


https://www.vmware.com/security/advisories/VMSA-2020-0011.html


0x05 ʱ¼äÏß


2020-05-28 VMwareÐû²¼Îó²îͨ¸æ

2020-06-01 VSRCÐû²¼Îó²îͨ¸æ

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾