¡¾·ì϶¹«¸æ¡¿VMware ESXiÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶(CVE-2021-21994)
°ä²¼¹¦·ò 2021-07-150x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-21994 | ʱ ¼ä | 2021-07-15 |
Àà ÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
¹¥»÷¸´ÔÓ¶È | ¸ß | ¿ÉÓÃÐÔ | µÍ |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ·ì϶ÏêÇé

2021Äê7ÔÂ13ÈÕ£¬Vmware°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËVMware ESXi ÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2021-21994£©ºÍÒ»¸ö»Ø¾ø·þÎñ·ì϶£¨CVE-2021-21995£©£¬Õâ2¸ö·ì϶ӰÏìVMware ESXiºÍVMware Cloud Foundation£¬ËüÃǵÄCVSSv3¸ù»ùÆÀ·Ö±ðÀëΪ7.0ºÍ5.3¡£
VMware ESXi SFCBÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶(CVE-2021-21994)
ÓÉÓÚESXi ÖÐʹÓÃµÄ SFCB£¨Small Footprint CIM Broker£©´æÔÚÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¬¿ÉÄܽӼûESXi ÉϵÄ5989¶Ë¿ÚµÄ¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶·¢ËͶñÒâÒªÇóÀ´Èƹý SFCB Éí·ÝÑéÖ¤¡£µ«Ä¬ÈÏÇé¿öÏ£¬ESXi ÉÏδÆôÓà SFCB ·þÎñ¡£
VMware ESXi OpenSLP »Ø¾ø·þÎñ·ì϶ (CVE-2021-21995)
ÓÉÓÚ¶ÑÔ½½ç¶ÁÈ¡ÎÊÌ⣬ESXi ÖÐʹÓÃµÄ OpenSLP ´æÔڻؾø·þÎñ·ì϶¡£¿ÉÄܽӼûESXi ÉϵÄ427¶Ë¿ÚµÄ¹¥»÷ÕßÄܹ»ÔÚ OpenSLP ·þÎñÖд¥·¢¶ÑÔ½½ç¶ÁÈ¡£¬´Ó¶øµ¼Ö»ؾø·þÎñ¡£
0x02 ´ëÖý¨Òé
ĿǰVMwareÒÑÔÚ´ó²¿ÃÅÊÜÓ°Ïì²úÆ·Öн¨¸´ÁËÕâ2¸ö·ì϶£¬½¨ÒéʵʱÉý¼¶¸üе½ÒÔϰ汾£º
ÊÜÓ°Ïì°æ±¾ | ½¨¸´°æ±¾ | ½¨¸´²½Öè |
ESXi 7.0 | ESXi70U2-17630552 | CVE-2021-21994£ºhttps://kb.vmware.com/s/article/1025757 CVE-2021-21995£º https://kb.vmware.com/s/article/76372 |
ESXi 6.7 | ESXi670-202103101-SG | |
ESXi 6.5 | ESXi650-202107401-SG | |
Cloud Foundation (ESXi) 4.x | ÔÝÎÞ²¹¶¡ | |
Cloud Foundation (ESXi) 3.x | 3.10.2 |
0x03 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2021-0014.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21994
https://nvd.nist.gov/vuln/detail/CVE-2021-21994
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-07-15 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD¹ÙÍø£ºwww.cnvd.org.cn
CNNVD¹ÙÍø£ºwww.cnnvd.org.cn
CVE¹ÙÍø£ºcve.mitre.org
NVD¹ÙÍø£ºnvd.nist.gov
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºwww.first.org
0x06 ¹ØÓÚGA»Æ½ð¼×
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ