VMware | ¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-05-310x00 ·ì϶¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
ESXi,Workstation,Fusion,VMRC for Mac,Horizon Client for Mac |
CVE-2020-3957 |
LPE |
¸ßΣ |
·ñ |
Fusion 11.x VMRC for Mac <= 11.x Horizon Client for Mac <= 5.x |
|
CVE-2020-3958 |
DOS |
ÖÐΣ |
ÊÇ |
ESXi 6.5,6.7 Workstation 15.x Fusion 11.x |
|
|
CVE-2020-3959 |
ML |
µÍΣ |
·ñ |
0x01 ·ì϶ÏêÇé
VMwareÐé¹¹»úÈí¼þ£¬ÊÇÈ«Çò×ÀÃæµ½Êý¾ÝÖÐÐÄÐé¹¹»¯½â¾ö¹æ»®µÄ¸¨µ¼³§ÉÌ¡£È«Çò·ÖÆç¹æÄ£µÄ¿Í»§ÒÀ¸½VMwareÀ´½µµÍ³É±¾ºÍÔËÓªÓöȡ¢È·±£ÒµÎñ³ÖÐøÐÔ¡¢¼ÓÇ¿°²È«ÐÔ²¢×ßÏòÂÌÉ«¡£
2020Äê5ÔÂ28ÈÕVMware°ä²¼°²È«¸üУ¬½¨¸´ÁËVMware ESXi£¬Workstation£¬Fusion£¬VMware Remote ConsoleºÍHorizon ClientÖеĶà¸ö°²È«·ì϶£¨CVE-2020-3957£¬CVE-2020-3958£¬CVE-2020-3959£©£¬¾ßÌåÐÅÏ¢ÈçÏ£º
CVE-2020-3957ÊÇVMware Fusion£¬VMRCºÍHorizon Client²úÆ·Öеı¾µØÌØÈ¨Éý¼¶·ì϶¡£¸Ã·ì϶ԴÓÚ·þÎñ¿ªÆô·¨Ê½ÖеIJ鳹¦·òʹÓù¦·ò£¨TOCTOU£©ÎÊÌ⣬¹¥»÷Õß¿ÉÀûÓô˷ì϶½«Í¨³£Óû§È¨ÏÞÌáÉýÖÁrootȨÏÞ¡£
CVE-2020-3958ÊÇVMware ESXi£¬WorkstationºÍFusion²úÆ·ÖеÄShaderÖ°ÄܵĻؾø·þÎñ·ì϶¡£ÒªÀûÓô˷ì϶£¬¹¥»÷Õß±ØÐë¿ÉÄܽӼûÆôÓÃÁË3DͼÐεÄÐé¹¹»ú£¨ÔÚESXiÉÏĬÈÏδÆôÓã¬ÔÚWorkstationºÍFusionÉÏĬÈÏÒÑÆôÓã©¡£¹¥»÷Õß¿ÉÀûÓô˷ì϶ʹÐé¹¹»úµÄvmx¹ý³Ì±ÀÀ££¬´Ó¶øµ¼Ö»ؾø·þÎñ¡£
CVE-2020-3959ÊÇVMware ESXi£¬WorkstationºÍFusion²úÆ·ÖеÄVMCIÄ£¿éÖеÄÄÚ´æÐ¹Â©·ì϶¡£ÓµÓб¾µØ·ÇÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¿ÉÀûÓø÷ì϶ʹÐé¹¹»úµÄvmx¹ý³Ì±ÀÀ££¬´Ó¶øµ¼Ö»ؾø·þÎñ¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬Õë¶Ô·ÖÆçµÄ²úÆ·ºÍ·ì϶ÓоßÌåµÄ½¨¸´°æ±¾£¬²Î¿¼ÒÔϱí¸ñ£º
0x03 ÓйØÐÂÎÅ
https://www.basquecybersecurity.eus/es/avisos/tecnicos/multiples-vulnerabilidades-productos-vmware-20200529.html
0x04 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2020-0011.html
0x05 ¹¦·òÏß
2020-05-28 VMware°ä²¼·ì϶²¼¸æ
2020-06-01 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ