Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | VMware vCenter ServerÈÏÖ¤ÏÂÁîÖ´ÐÐÎó²î |
CVE ID | CVE-2025-41225 |
Îó²îÀàÐÍ | ÏÂÁîÖ´ÐÐ | ·¢Ã÷ʱ¼ä | 2025-05-22 |
Îó²îÆÀ·Ö | 8.8 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍâµØ | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
vCenterÊÇVMwareÌṩµÄ¼¯ÖÐÖÎÀíÆ½Ì¨£¬£¬£¬ÓÃÓÚÖÎÀíVMware vSphereÇéÐÎÖеÄÐéÄ⻯×ÊÔ´¡£¡£¡£¡£¡£¡£¡£ËüÔÊÐíÖÎÀíÔ±¶ÔÐéÄâ»ú¡¢Ö÷»ú¡¢´æ´¢ºÍÍøÂç¾ÙÐÐͳһÖÎÀíºÍ¼à¿Ø¡£¡£¡£¡£¡£¡£¡£vCenterÌṩ¹¦Ð§ÈçÐéÄâ»ú°²ÅÅ¡¢×Ô¶¯»¯ÖÎÀí¡¢×ÊÔ´ÓÅ»¯ºÍ¸ß¿ÉÓÃÐÔ£¬£¬£¬×ÊÖúÆóÒµÌá¸ßÐéÄ⻯ÇéÐεÄЧÂʺÍÎÞаÐÔ¡£¡£¡£¡£¡£¡£¡£vCenterÊÇ´ó¹æÄ£Êý¾ÝÖÐÐĺÍÔÆÇéÐÎÖв»¿É»òȱµÄÖÎÀí¹¤¾ß£¬£¬£¬Ö§³Ö¼¯ÈºÖÎÀí¡¢¸ºÔØÆ½ºâºÍ¹ÊÕϻָ´µÈ¸ß¼¶ÌØÕ÷¡£¡£¡£¡£¡£¡£¡£
2025Äê5ÔÂ22ÈÕ£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½VMwareÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬Ö¸³öVMware vCenter±£´æÈÏÖ¤ÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔھ߱¸½¨Éè»òÐ޸ľ¯±¨ÒÔ¼°Ö´Ðо籾²Ù×÷ȨÏÞʱ£¬£¬£¬¿ÉÄÜʹÓøÃÎó²îÔÚvCenter ServerÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£Èô¸ÃÎó²î±»ÀÖ³ÉʹÓ㬣¬£¬¹¥»÷Õß¿ÉÄÜ»ñµÃϵͳ¿ØÖÆÈ¨ÏÞ»òÀÄÓÃϵͳ£¬£¬£¬´øÀ´ÑÏÖØµÄÇ徲Σº¦¡£¡£¡£¡£¡£¡£¡£Îó²î¼¶±ð¸ßΣ£¬£¬£¬Îó²îÆÀ·Ö8.8·Ö¡£¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
vCenter Server 8.0 < 8.0 U3evCenter Server 7.0 < 7.0 U3vVMware Cloud Foundation (vCenter) = 5.xVMware Cloud Foundation (vCenter) = 4.5.xVMware Telco Cloud Platform (vCenter) 5.x/4.x/3.x/2.x < 8.0 U3eVMware Telco Cloud Infrastructure (vCenter) 3.x < 8.0 U3eVMware Telco Cloud Infrastructure (vCenter) 2.x < 7.0 U3v
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶¡£¡£¡£¡£¡£¡£¡£vCenter Server 8.0 >= 8.0 U3evCenter Server 7.0 >= 7.0 U3vVMware Telco Cloud Platform (vCenter) 5.x/4.x/3.x/2.x >= 8.0 U3eVMware Telco Cloud Infrastructure (vCenter) 3.x >= 8.0 U3eVMware Telco Cloud Infrastructure (vCenter) 2.x >= 7.0 U3v
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25717