¡¾Â©¶´Í¨¸æ¡¿VMware ESXiÉí·ÝÑéÖ¤ÈÆ¹ý©¶´(CVE-2021-21994)
Ðû²¼Ê±¼ä 2021-07-150x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-21994 | ʱ ¼ä | 2021-07-15 |
Àà ÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | |
¹¥»÷ÅÓ´ó¶È | ¸ß | ¿ÉÓÃÐÔ | µÍ |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ©¶´ÏêÇé
2021Äê7ÔÂ13ÈÕ£¬VmwareÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËVMware ESXi ÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¨CVE-2021-21994£©ºÍÒ»¸ö¾Ü¾ø·þÎñ©¶´£¨CVE-2021-21995£©£¬Õâ2¸ö©¶´Ó°ÏìVMware ESXiºÍVMware Cloud Foundation£¬ËüÃǵÄCVSSv3»ù±¾ÆÀ·Ö·Ö±ðΪ7.0ºÍ5.3¡£
VMware ESXi SFCBÉí·ÝÑéÖ¤ÈÆ¹ý©¶´(CVE-2021-21994)
ÓÉÓÚESXi ÖÐʹÓÃµÄ SFCB£¨Small Footprint CIM Broker£©´æÔÚÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¬Äܹ»·ÃÎÊESXi ÉϵÄ5989¶Ë¿ÚµÄ¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´·¢ËͶñÒâÇëÇóÀ´Èƹý SFCB Éí·ÝÑéÖ¤¡£µ«Ä¬ÈÏÇé¿öÏ£¬ESXi ÉÏδÆôÓà SFCB ·þÎñ¡£
VMware ESXi OpenSLP ¾Ü¾ø·þÎñ©¶´ (CVE-2021-21995)
ÓÉÓÚ¶ÑÔ½½ç¶ÁÈ¡ÎÊÌ⣬ESXi ÖÐʹÓÃµÄ OpenSLP ´æÔھܾø·þÎñ©¶´¡£Äܹ»·ÃÎÊESXi ÉϵÄ427¶Ë¿ÚµÄ¹¥»÷Õß¿ÉÒÔÔÚ OpenSLP ·þÎñÖд¥·¢¶ÑÔ½½ç¶ÁÈ¡£¬´Ó¶øµ¼Ö¾ܾø·þÎñ¡£
0x02 ´¦Öý¨Òé
ĿǰVMwareÒÑÔÚ´ó²¿ÃÅÊÜÓ°Ïì²úÎïÖÐÐÞ¸´ÁËÕâ2¸ö©¶´£¬½¨Ò鼰ʱÉý¼¶¸üе½ÒÔϰ汾£º
ÊÜÓ°Ïì°æ±¾ | ÐÞ¸´°æ±¾ | ÐÞ¸´ÒªÁì |
ESXi 7.0 | ESXi70U2-17630552 | CVE-2021-21994£ºhttps://kb.vmware.com/s/article/1025757 CVE-2021-21995£º https://kb.vmware.com/s/article/76372 |
ESXi 6.7 | ESXi670-202103101-SG | |
ESXi 6.5 | ESXi650-202107401-SG | |
Cloud Foundation (ESXi) 4.x | ÔÝÎÞ²¹¶¡ | |
Cloud Foundation (ESXi) 3.x | 3.10.2 |
0x03 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2021-0014.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21994
https://nvd.nist.gov/vuln/detail/CVE-2021-21994
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-07-15 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD¹ÙÍø£ºwww.cnvd.org.cn
CNNVD¹ÙÍø£ºwww.cnnvd.org.cn
CVE¹ÙÍø£ºcve.mitre.org
NVD¹ÙÍø£ºnvd.nist.gov
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºwww.first.org
0x06 ¹ØÓÚ¶«Éƽ̨
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º