Citrix Endpoint Management¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-08-13

0x00 ·ì϶¸ÅÊö


2020Äê8ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬Citrix¹Ù·½°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËÎå¸ö°²È«·ì϶£¨CVE-2020-8208¡¢CVE-2020-8209¡¢CVE-2020-8210¡¢CVE-2020-8211¡¢CVE-2020-8212£©£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶ӰÏìCitrix Endpoint Management£¨CEM£©£¨Ò²³ÆÎªXenMobileServer£©µÄ¶à¸ö°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£


0x01 ·ì϶ÏêÇé


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



Citrix XenMobile ServerÊÇÃÀ¹úCitrix Systems¹«Ë¾µÄÒ»Ì×ÒÆ¶¯ÖÎÀí½â¾ö¹æ»®¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹æ»®¿ÉÄÜÖÎÀíÒÆ¶¯É豸¡¢Ôì¶©ÒÆ¶¯Õ½ÊõºÍºÏ¹æÐԹ涨¡¢Éî¿ÌÏàÊ¶ÒÆ¶¯Òƶ¯ÍøÂçÔËÐÐÇé¿öµÈ¡£¡£¡£¡£¡£¡£¡£¡£±¾µØ²¿ÊðµÄCitrix XenMobileÌṩÁËÒ»¸öͳһµÄ½Ó¿Ú£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÒ»¸öµ¥Ò»µÄƽ̨ÖÎÀíÔ±¹¤µĄ̈ʽ»ú£¬£¬£¬£¬£¬£¬£¬±Ê¼Ç±¾ºÍÒÆ¶¯É豸£¨Æ½°åµçÄÔºÍÖÇÄÜÊÖ»ú£©¡£¡£¡£¡£¡£¡£¡£¡£

ÕâÎå¸ö·ì϶ÖÐÓÐÁ½¸ö±»ÆÀΪ³¬Î£·ì϶£¨CVE-2020-8208¡¢CVE-2020-8209£©£¬£¬£¬£¬£¬£¬£¬·ì϶µ¼ÖÂδ¾­Éí·ÝÈÏÖ¤µÄ¹¥»÷Õ߿ɻñÈ¡ÖÎÀíÔ±½ÚÔìȨÏÞ£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊÕÊÜXenMobile Servers¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄXenMobileServer°æ±¾ÈçÏ£º

? XenMobile Server < 10.12 RP2

? XenMobile Server < 10.11 RP4

? XenMobile Server < 10.10 RP6

? XenMobile Server < 10.9 RP5

ÆäËûÈý¸ö·ì϶µÄÑϳÁˮƽ±»ÆÀΪÖÐΣºÍµÍΣ£¨CVE-2020-8210¡¢CVE-2020-8211¡¢CVE-2020-8212£©£¬£¬£¬£¬£¬£¬£¬·ì϶µ¼ÖÂCEMÖÎÀíÔ±¿É½Ó¼ûδÊÚȨµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄXenMobileServer°æ±¾ÈçÏ£º

? XenMobile Server < 10.12 RP3

? XenMobile Server < 10.11 RP6

? XenMobile Server < 10.10 RP6

? XenMobile Server < 10.9 RP5

Citrix½¨Òé¿Í»§Á¢¼´¸üÐÂXenMobile Server£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕߺÜÓпÉÄÜ»á½ô½Ó×ÅÆðͷɨÃè²éÕÒ´àÈõµÄ·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬²¢ÀûÓÃÕâЩ·ì϶½øÐй¥»÷¡£¡£¡£¡£¡£¡£¡£¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌÒÑÕë¶Ô·ÖÆçµÄ°æ±¾°ä²¼²¹¶¡£¬£¬£¬£¬£¬£¬£¬¾ßÌåÄÚÈÝÈçÏ£º

? XenMobile Server 10.12 RP3: https://support.citrix.com/article/CTX277473

? XenMobile Server 10.11 RP6: https://support.citrix.com/article/CTX277698

? XenMobile Server 10.10 RP6: https://support.citrix.com/article/CTX279101

? XenMobile Server 10.9 RP5: https://support.citrix.com/article/CTX279098


0x03 ÓйØÐÂÎÅ


https://www.bleepingcomputer.com/news/security/citrix-fixes-critical-bugs-allowing-takeover-of-xenmobile-servers/


0x04 ²Î¿¼Á´½Ó


https://support.citrix.com/article/CTX277457


0x05 ¹¦·òÏß


2020-08-11 Citrix¹Ù·½°ä²¼°²È«²¼¸æ

2020-08-13 VSRC°ä²¼·ì϶¹«¸æ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website