VMware | ¶à¸öÇå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-05-310x00 Îó²î¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
Îó²îÆ·¼¶ |
Ô¶³ÌʹÓà |
Ó°Ïì¹æÄ£ |
|
ESXi,Workstation,Fusion,VMRC for Mac,Horizon Client for Mac |
CVE-2020-3957 |
LPE |
¸ßΣ |
·ñ |
Fusion 11.x VMRC for Mac <= 11.x Horizon Client for Mac <= 5.x |
|
CVE-2020-3958 |
DOS |
ÖÐΣ |
ÊÇ |
ESXi 6.5,6.7 Workstation 15.x Fusion 11.x |
|
|
CVE-2020-3959 |
ML |
µÍΣ |
·ñ |
0x01 Îó²îÏêÇé
VMwareÐéÄâ»úÈí¼þ£¬£¬ÊÇÈ«Çò×ÀÃæµ½Êý¾ÝÖÐÐÄÐéÄ⻯½â¾ö¼Æ»®µÄÏòµ¼³§ÉÌ¡£¡£¡£È«Çò²î±ð¹æÄ£µÄ¿Í»§ÒÀÀµVMwareÀ´½µµÍ±¾Ç®ºÍÔËÓªÓöȡ¢È·±£ÓªÒµÒ»Á¬ÐÔ¡¢ÔöÇ¿Çå¾²ÐÔ²¢×ßÏòÂÌÉ«¡£¡£¡£
2020Äê5ÔÂ28ÈÕVMwareÐû²¼Çå¾²¸üУ¬£¬ÐÞ¸´ÁËVMware ESXi£¬£¬Workstation£¬£¬Fusion£¬£¬VMware Remote ConsoleºÍHorizon ClientÖеĶà¸öÇå¾²Îó²î£¨CVE-2020-3957£¬£¬CVE-2020-3958£¬£¬CVE-2020-3959£©£¬£¬ÏêϸÐÅÏ¢ÈçÏ£º
CVE-2020-3957ÊÇVMware Fusion£¬£¬VMRCºÍHorizon Client²úÆ·ÖеÄÍâµØÌØÈ¨Éý¼¶Îó²î¡£¡£¡£¸ÃÎó²îÔ´ÓÚЧÀÍ¿ªÆô³ÌÐòÖеļì²éʱ¼äʹÓÃʱ¼ä£¨TOCTOU£©ÎÊÌ⣬£¬¹¥»÷Õß¿ÉʹÓôËÎó²î½«Í¨Ë×Óû§È¨ÏÞÌáÉýÖÁrootȨÏÞ¡£¡£¡£
CVE-2020-3958ÊÇVMware ESXi£¬£¬WorkstationºÍFusion²úÆ·ÖеÄShader¹¦Ð§µÄ¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£ÒªÊ¹ÓôËÎó²î£¬£¬¹¥»÷Õß±ØÐèÄܹ»»á¼ûÆôÓÃÁË3DͼÐεÄÐéÄâ»ú£¨ÔÚESXiÉÏĬÈÏδÆôÓ㬣¬ÔÚWorkstationºÍFusionÉÏĬÈÏÒÑÆôÓã©¡£¡£¡£¹¥»÷Õß¿ÉʹÓôËÎó²îʹÐéÄâ»úµÄvmxÀú³ÌÍ߽⣬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£
CVE-2020-3959ÊÇVMware ESXi£¬£¬WorkstationºÍFusion²úÆ·ÖеÄVMCIÄ£¿£¿éÖеÄÄÚ´æ×ß©Îó²î¡£¡£¡£¾ßÓÐÍâµØ·ÇÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¿ÉʹÓøÃÎó²îʹÐéÄâ»úµÄvmxÀú³ÌÍ߽⣬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬Õë¶Ô²î±ðµÄ²úÆ·ºÍÎó²îÓÐÏêϸµÄÐÞ¸´°æ±¾£¬£¬²Î¿¼ÒÔϱí¸ñ£º
0x03 Ïà¹ØÐÂÎÅ
https://www.basquecybersecurity.eus/es/avisos/tecnicos/multiples-vulnerabilidades-productos-vmware-20200529.html
0x04 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2020-0011.html
0x05 ʱ¼äÏß
2020-05-28 VMwareÐû²¼Îó²îͨ¸æ
2020-06-01 VSRCÐû²¼Îó²îͨ¸æ


¾©¹«Íø°²±¸11010802024551ºÅ