CVE-2020-3952 | VMwareÐÅϢй¶·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-12

0x00 ·ì϶¸ÅÊö


CVE ID

CVE-2020-3952

ʱ     ¼ä

2020-04-11

Àà  ÐÍ

ÐÅϢй¶

µÈ     ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ
ÊÇ

Ó°ÏìÁìÓò

WindowsºÍÐé¹¹É豸ÉϵÄvCenter  Server 6.7



0x01 ·ì϶ÏêÇé


VMware vCenter ServerÊÇÃÀ¹úÍþ¨VMware£©¹«Ë¾µÄÒ»Ì×·þÎñÆ÷ºÍÐé¹¹»¯ÖÎÀíÈí¼þ¡£¸ÃÈí¼þÌṩÁËÒ»¸öÓÃÓÚÖÎÀíVMwarevSphere»·¾³µÄ¼¯ÖÐʽƽ̨£¬¿É×Ô¶¯Ö´Ðкͽ»¸¶Ðé¹¹»ù´¡¼Ü¹¹¡£


VMware½¨¸´ÁËÒ»¸öÑϳÁ·ì϶CVE-2020-3952£¬CVSSÆÀ·ÖΪ10¡£¸Ã·ì϶ÊÇÓëĿ¼·þÎñÓйصÄÐÅϢй¶·ì϶£¬¿É±»ÀûÓÃÀ´·ÛËévCenterServer¡£


WMware°ä²¼µÄ²¼¸æÖаµÊ¾£ºÔÚijЩÇé¿öÏ£¬×÷ΪǶÈëʽ»ò±í²¿Platform Services Controller£¨PSC£©Ò»²¿ÃŵÄVMware vCenter Server¸½´øµÄvmdirÎÞ·¨ÕýµÄÈ·ÏÖ½Ó¼û½ÚÔì¡£¹¥»÷Õß¿ÉÄÜÌáÈ¡µ½¸ß¶ÈÃô¸ÐÐÅÏ¢£¬ÓÃÓÚ·ÛËévCenter Server»òÆäËûÒÀÀµvmdir½øÐÐÉí·ÝÑéÖ¤µÄ·þÎñ¡£

   

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¸Ã·ì϶ӰÏìWindowsºÍÐé¹¹É豸ÉϵÄvCenterServer 6.7°æ±¾£¬²¢ÒÑͨ¹ý6.7u3f°æ±¾½øÐÐÁ˽¨²¹¡£VmwareÇ¿µ÷£¬Ö»ÓдÓÏÈǰ°æ±¾Éý¼¶×°Öúó£¬vCenter Server²Å»áÊÜÓ°Ïì¡£ÈôÊÇÓû§Ö±½Ó×°ÖÃ6.7°æ±¾£¬Ôò²»»áÊܵ½Ó°Ïì¡£


0x02 ´ëÖý¨Òé


Éý¼¶vCenter Server µ½6.7u3f°æ±¾£º

https://my.vmware.com/web/vmware/details?productId=742&rPId=44888&downloadGroup=VC67U3F


0x03 ÓйØÐÂÎÅ


https://securityaffairs.co/wordpress/101388/security/cve-2020-3952-vmware-vcenter-server.html


0x04 ²Î¿¼Á´½Ó


https://www.vmware.com/security/advisories/VMSA-2020-0006.html


0x05 ¹¦·òÏß



2020-04-09 Vmware¹Ù·½°ä²¼·ì϶

2020-04-10 CVE°ä²¼¸Ã·ì϶