VMware | ¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-05-310x00 ·ì϶¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
ESXi,Workstation,Fusion,VMRC for Mac,Horizon Client for Mac |
CVE-2020-3957 |
LPE |
¸ßΣ |
·ñ |
Fusion 11.x VMRC for Mac <= 11.x Horizon Client for Mac <= 5.x |
|
CVE-2020-3958 |
DOS |
ÖÐΣ |
ÊÇ |
ESXi 6.5,6.7 Workstation 15.x Fusion 11.x |
|
|
CVE-2020-3959 |
ML |
µÍΣ |
·ñ |
0x01 ·ì϶ÏêÇé
VMwareÐé¹¹»úÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÊÇÈ«Çò×ÀÃæµ½Êý¾ÝÖÐÐÄÐé¹¹»¯½â¾ö¹æ»®µÄ¸¨µ¼³§ÉÌ¡£¡£¡£¡£¡£È«Çò·ÖÆç¹æÄ£µÄ¿Í»§ÒÀ¸½VMwareÀ´½µµÍ³É±¾ºÍÔËÓªÓöȡ¢È·±£ÒµÎñ³ÖÐøÐÔ¡¢¼ÓÇ¿°²È«ÐÔ²¢×ßÏòÂÌÉ«¡£¡£¡£¡£¡£
2020Äê5ÔÂ28ÈÕVMware°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËVMware ESXi£¬£¬£¬£¬£¬£¬£¬Workstation£¬£¬£¬£¬£¬£¬£¬Fusion£¬£¬£¬£¬£¬£¬£¬VMware Remote ConsoleºÍHorizon ClientÖеĶà¸ö°²È«·ì϶£¨CVE-2020-3957£¬£¬£¬£¬£¬£¬£¬CVE-2020-3958£¬£¬£¬£¬£¬£¬£¬CVE-2020-3959£©£¬£¬£¬£¬£¬£¬£¬¾ßÌåÐÅÏ¢ÈçÏ£º
CVE-2020-3957ÊÇVMware Fusion£¬£¬£¬£¬£¬£¬£¬VMRCºÍHorizon Client²úÆ·Öеı¾µØÌØÈ¨Éý¼¶·ì϶¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚ·þÎñ¿ªÆô·¨Ê½ÖеIJ鳹¦·òʹÓù¦·ò£¨TOCTOU£©ÎÊÌ⣬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶½«Í¨³£Óû§È¨ÏÞÌáÉýÖÁrootȨÏÞ¡£¡£¡£¡£¡£
CVE-2020-3958ÊÇVMware ESXi£¬£¬£¬£¬£¬£¬£¬WorkstationºÍFusion²úÆ·ÖеÄShaderÖ°ÄܵĻؾø·þÎñ·ì϶¡£¡£¡£¡£¡£ÒªÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß±ØÐë¿ÉÄܽӼûÆôÓÃÁË3DͼÐεÄÐé¹¹»ú£¨ÔÚESXiÉÏĬÈÏδÆôÓ㬣¬£¬£¬£¬£¬£¬ÔÚWorkstationºÍFusionÉÏĬÈÏÒÑÆôÓã©¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓô˷ì϶ʹÐé¹¹»úµÄvmx¹ý³Ì±ÀÀ££¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£
CVE-2020-3959ÊÇVMware ESXi£¬£¬£¬£¬£¬£¬£¬WorkstationºÍFusion²úÆ·ÖеÄVMCIÄ£¿£¿£¿£¿£¿éÖеÄÄÚ´æÐ¹Â©·ì϶¡£¡£¡£¡£¡£ÓµÓб¾µØ·ÇÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¿ÉÀûÓø÷ì϶ʹÐé¹¹»úµÄvmx¹ý³Ì±ÀÀ££¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬£¬£¬Õë¶Ô·ÖÆçµÄ²úÆ·ºÍ·ì϶ÓоßÌåµÄ½¨¸´°æ±¾£¬£¬£¬£¬£¬£¬£¬²Î¿¼ÒÔϱí¸ñ£º
0x03 ÓйØÐÂÎÅ
https://www.basquecybersecurity.eus/es/avisos/tecnicos/multiples-vulnerabilidades-productos-vmware-20200529.html
0x04 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2020-0011.html
0x05 ¹¦·òÏß
2020-05-28 VMware°ä²¼·ì϶²¼¸æ
2020-06-01 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ