CVE-2020-3952 | VMwareÐÅϢй¶Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-04-12

0x00 Îó²î¸ÅÊö


CVE ID

CVE-2020-3952

ʱ     ¼ä

2020-04-11

Àà  ÐÍ

ÐÅϢй¶

µÈ     ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ
ÊÇ

Ó°Ïì¹æÄ£

WindowsºÍÐéÄâÉè±¹ØÁ¬ÄvCenter  Server 6.7



0x01 Îó²îÏêÇé


VMware vCenter ServerÊÇÃÀ¹úÍþ¨VMware£©¹«Ë¾µÄÒ»Ì×ЧÀÍÆ÷ºÍÐéÄ⻯ÖÎÀíÈí¼þ¡£¡£¡£¡£ ¡£¸ÃÈí¼þÌṩÁËÒ»¸öÓÃÓÚÖÎÀíVMwarevSphereÇéÐεļ¯ÖÐʽƽ̨£¬£¬£¬£¬£¬¿É×Ô¶¯ÊµÑéºÍ½»¸¶ÐéÄâ»ù´¡¼Ü¹¹¡£¡£¡£¡£ ¡£


VMwareÐÞ¸´ÁËÒ»¸öÑÏÖØÎó²îCVE-2020-3952£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ10¡£¡£¡£¡£ ¡£¸ÃÎó²îÊÇÓëĿ¼ЧÀÍÏà¹ØµÄÐÅϢй¶Îó²î£¬£¬£¬£¬£¬¿É±»Ê¹ÓÃÀ´ÆÆËðvCenterServer¡£¡£¡£¡£ ¡£


WMwareÐû²¼µÄͨ¸æÖÐÌåÏÖ£ºÔÚijЩÇéÐÎÏ£¬£¬£¬£¬£¬×÷ΪǶÈëʽ»òÍⲿPlatform Services Controller£¨PSC£©Ò»²¿·ÖµÄVMware vCenter Server¸½´øµÄvmdirÎÞ·¨×¼È·ÊµÏÖ»á¼û¿ØÖÆ¡£¡£¡£¡£ ¡£¹¥»÷ÕßÄܹ»ÌáÈ¡µ½¸ß¶ÈÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬ÓÃÓÚÆÆËðvCenter Server»òÆäËûÒÀÀµvmdir¾ÙÐÐÉí·ÝÑéÖ¤µÄЧÀÍ¡£¡£¡£¡£ ¡£

   

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


¸ÃÎó²îÓ°ÏìWindowsºÍÐéÄâÉè±¹ØÁ¬ÄvCenterServer 6.7°æ±¾£¬£¬£¬£¬£¬²¢ÒÑͨ¹ý6.7u3f°æ±¾¾ÙÐÐÁËÐÞ²¹¡£¡£¡£¡£ ¡£VmwareÇ¿µ÷£¬£¬£¬£¬£¬Ö»ÓдÓÏÈǰ°æ±¾Éý¼¶×°Öú󣬣¬£¬£¬£¬vCenter Server²Å»áÊÜÓ°Ïì¡£¡£¡£¡£ ¡£ÈôÊÇÓû§Ö±½Ó×°ÖÃ6.7°æ±¾£¬£¬£¬£¬£¬Ôò²»»áÊܵ½Ó°Ïì¡£¡£¡£¡£ ¡£


0x02 ´¦Öóͷ£½¨Òé


Éý¼¶vCenter Server µ½6.7u3f°æ±¾£º

https://my.vmware.com/web/vmware/details?productId=742&rPId=44888&downloadGroup=VC67U3F


0x03 Ïà¹ØÐÂÎÅ


https://securityaffairs.co/wordpress/101388/security/cve-2020-3952-vmware-vcenter-server.html


0x04 ²Î¿¼Á´½Ó


https://www.vmware.com/security/advisories/VMSA-2020-0006.html


0x05 ʱ¼äÏß



2020-04-09 Vmware¹Ù·½Ðû²¼Îó²î

2020-04-10 CVEÐû²¼¸ÃÎó²î