CVE-2020-3992 | Vmware ESXiÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-10-21

0x00 Îó²î¸ÅÊö

CVE   ID

CVE-2020-3992

ʱ    ¼ä

2020-10-21

Àà    ÐÍ

RCE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


 

VMware ESXiÊÇ¿ÉÖ±½Ó×°ÖÃÔÚÎïÀíЧÀÍÆ÷ÉϵÄÂã»ú hypervisor¡£¡£¡£¡£¡£¡£ËüÄܹ»Ö±½Ó»á¼û²¢¿ØÖƵײã×ÊÔ´£¬£¬£¬£¬£¬£¬£¬Òò´Ë¿É¶ÔÓ²¼þ¾ÙÐÐÓÐÓ÷ÖÇø£¬£¬£¬£¬£¬£¬£¬´Ó¶øÕûºÏÓ¦Óò¢Ï÷¼õ±¾Ç®¡£¡£¡£¡£¡£¡£VMware ESXiÊÇÒµ½çÁìÏȵĸßЧϵͳ¼Ü¹¹£¬£¬£¬£¬£¬£¬£¬ÔÚ¿É¿¿ÐÔ¡¢ÐÔÄܺÍÖ§³Ö·½ÃæÊ÷Á¢ÁËÐÐÒµ±ê¸Ë¡£¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

 

2020Äê10ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬VmwareÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬VMware ESXiÖеÄOpenSLP×é¼þ±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2020-3992)£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.8¡£¡£¡£¡£¡£¡£ÓÉÓÚOpenSLP±£´æÊͷźó±»ÖØÊ¹ÓÃÎÊÌ⣬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɻá¼ûESXiËÞÖ÷»úÉϵÄ427¶Ë¿Ú´¥·¢OpenSLPЧÀÍÖеġ°use-after-free¡±£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚVmwareÒÑÐû²¼Ïà¹Ø²¹¶¡£¬£¬£¬£¬£¬£¬£¬½¨ÒéʵʱÐÞ¸´¡£¡£¡£¡£¡£¡£

 

ÊÜÓ°Ïì²úÆ·

°æ±¾

Çå¾²°æ±¾

ÏÂÔØÁ´½Ó

²Ù×÷ÊÖ²á

ESXi

7.0

ESXi_7.0.1-0.0.16850804

https://my.vmware.com/group/vmware/patch

https://docs.vmware.com/en/VMware-vSphere/7.0/rn/vsphere-esxi-701-release-notes.html

ESXi

6.7

ESXi670-202010401-SG

https://docs.vmware.com/en/VMware-vSphere/6.7/rn/esxi670-202010001.html

ESXi

6.5

ESXi650-202010401-SG

https://docs.vmware.com/en/VMware-vSphere/6.5/rn/esxi650-202010001.html

VMware Cloud   Foundation (ESXi)

4.x

4.1

https://docs.vmware.com/en/VMware-Cloud-Foundation/4.1/rn/VMware-Cloud-Foundation-41-Release-Notes.html

VMware Cloud   Foundation (ESXi)

3.x

3.10.1.1

https://docs.vmware.com/en/VMware-Cloud-Foundation/3.10.1/rn/VMware-Cloud-Foundation-3101-Release-Notes.html#3.10.1.1

 

ÏÂÔØµØµã£º

https://my.vmware.com/cn/web/vmware/downloads/

ÔÝʱ²½·¥£º

ÈôÎÞ·¨Éý¼¶£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ýÔÚVMware ESXiÉϽûÓÃCIMЧÀÍÆ÷×÷ΪÔÝʱ½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡££¨´ËÒªÁì½öÊÊÓÃÓÚESXi£©

 

0x03 ²Î¿¼Á´½Ó

https://kb.vmware.com/s/article/76372

https://www.vmware.com/security/advisories/VMSA-2020-0023.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-3992

https://nvd.nist.gov/vuln/detail/CVE-2020-3992


0x04 ʱ¼äÏß

2020-10-20  VmwareÐû²¼Ç徲ͨ¸æ

2020-10-21  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

 

 image.png