¡¾Â©¶´Í¨¸æ¡¿VMware 2Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2022-02-16


0x00 ©¶´¸ÅÊö

2022Äê2ÔÂ15ÈÕ£¬VMwareÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËÆä¶à¸ö²úÎïÖеĶà¸öÄþ¾²Â©¶´£¬ÕâЩ©¶´Äܹ»µ¼ÖÂȨÏÞÌáÉý¡¢Î´ÊÚȨ·ÃÎÊ¡¢¾Ü¾ø·þÎñºÍÈÎÒâÃüÁîÖ´ÐеÈ¡£

 

0x01 ©¶´ÏêÇé

VMware±¾´ÎÐÞ¸´ÁË5¸öÓ°ÏìVMware ESXi¡¢Workstation ºÍ Fusion µÄÄþ¾²Â©¶´ÒÔ¼°1¸öÓ°ÏìVMware NSX Data Center for vSphere (NSX-V)µÄ©¶´£¬ÏêÇéÈçÏ£º

XHCI USB ¿ØÖÆÆ÷Use-after-free©¶´ (CVE-2021-22040)

VMware ESXi¡¢Workstation ºÍ Fusion ÔÚ XHCI USB ¿ØÖÆÆ÷ÖаüÂÞÒ»¸öÊͷźóʹÓé¶´£¬¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.4¡£ÔÚÐéÄâ»úÉϾßÓе±µØ¹ÜÀíȨÏ޵Ĺ¥»÷ÕßÄܹ»ÀûÓôË©¶´£¬ÒÔÔÚÖ÷»úÉÏÔËÐеÄÐéÄâ»úµÄVMX½ø³ÌµÄÉí·ÝÖ´ÐдúÂë¡£

 

UHCI USB ¿ØÖÆÆ÷Double-fetch©¶´ (CVE-2021-22041)

VMware ESXi¡¢Workstation ºÍ Fusion ÔÚ XHCI USB ¿ØÖÆÆ÷ÖаüÂÞÒ»¸öË«ÖØÌáȡ©¶´£¬¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.4¡£ÔÚÐéÄâ»úÉϾßÓе±µØ¹ÜÀíȨÏ޵Ĺ¥»÷ÕßÄܹ»ÀûÓôË©¶´£¬ÒÔÔÚÖ÷»úÉÏÔËÐеÄÐéÄâ»úµÄVMX½ø³ÌµÄÉí·ÝÖ´ÐдúÂë¡£

 

ESXi settingsd δÊÚȨ·ÃÎÊ©¶´ (CVE-2021-22042)

ÓÉÓÚVMX¿ÉÒÔ·ÃÎÊsettingsdÊÚȨƱ֤£¬µ¼ÖÂVMware ESXi´æÔÚδÊÚȨ·ÃÎÊ©¶´£¬¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.2¡£ÔÚVMX½ø³ÌÖоßÓÐÌØÈ¨µÄ¹¥»÷ÕßÄܹ»·ÃÎÊÒÔ¸ßȨÏÞÓû§Éí·ÝÔËÐеÄsettingsd·þÎñ¡£


ESXi settingsd TOCTOU ©¶´ (CVE-2021-22043)

VMware ESXi°üÂÞÒ»¸öTOCTOU£¨Time-of-check Time-of-use£©Â©¶´£¬¸Ã©¶´´æÔÚÓÚ´¦ÖÃÁÙʱÎļþµÄ·½Ê½ÖУ¬ÆäCVSSv3ÆÀ·ÖΪ8.2¡£Äܹ»·ÃÎÊ settingsd µÄ¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´Í¨¹ýдÈëÈÎÒâÎļþÀ´ÌáÉýÆäȨÏÞ¡£

 

ESXi slow HTTP POST ¾Ü¾ø·þÎñ©¶´ (CVE-2021-22050)

ESXi ÔÚ rhttpproxy ÖдæÔÚÒ»¸öslow HTTP POST ¾Ü¾ø·þÎñ©¶´£¬¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ5.3¡£Äܹ»ÍøÂç·ÃÎÊESXiµÄ¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´µ¼Ö¾ܾø·þÎñ¡£

 

VMware NSX Data Center for vSphere CLI shell ×¢Èë©¶´ (CVE-2022-22945)

VMware NSX Data Center for vSphere ÔÚ NSX Edge É豸×é¼þÖаüÂÞÒ»¸ö CLI shell×¢Èë©¶´£¬¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8¡£¶Ô NSX-Edge É豸 (NSX-V) ¾ßÓÐ SSH ·ÃÎÊȨÏ޵Ĺ¥»÷Õß¿ÉÒÔÒÔ root Éí·ÝÔÚϵͳÉÏÖ´ÐÐÈÎÒâÃüÁî¡£

 

Ó°Ï췶Χ

²úÎï

CVE

Ó°Ïì°æ±¾

ÐÞ¸´°æ±¾

ESXi

CVE-2021-22040, CVE-2021-22041

7.0 U3

ESXi70U3c-19193900

ESXi

CVE-2021-22040,   CVE-2021-22041

7.0 U2

ESXi70U2e-19290878

ESXi

CVE-2021-22040,   CVE-2021-22041

7.0 U1

ESXi70U1e-19324898

ESXi

CVE-2021-22040,   CVE-2021-22041

6.7

ESXi670-202111101-SG

ESXi

CVE-2021-22040,   CVE-2021-22041

6.5

ESXi650-202202401-SG

Fusion

CVE-2021-22040,   CVE-2021-22041

12.x

12.2.1

Workstation

CVE-2021-22040,   CVE-2021-22041

16.x

16.2.1

Cloud Foundation (ESXi)

CVE-2021-22040,   CVE-2021-22041

4.x

KB87646 (4.4)

Cloud Foundation (ESXi)

CVE-2021-22040,   CVE-2021-22041

3.x

3.11

ESXi

CVE-2021-22042,

CVE-2021-22043

7.0 U3

ESXi70U3c-19193900

ESXi

CVE-2021-22042,

CVE-2021-22043

7.0 U2

ESXi70U2e-19290878

ESXi

CVE-2021-22042,

CVE-2021-22043

7.0 U1

ESXi70U1e-19324898

Cloud Foundation (ESXi)

CVE-2021-22042, CVE-2021-22043

4.x

KB87646 (4.4)

ESXi

CVE-2021-22050

7.0

ESXi70U3c-19193900

ESXi

CVE-2021-22050

6.7

ESXi670-202111101-SG

ESXi

CVE-2021-22050

6.5

ESXi650-202110101-SG

Cloud Foundation (ESXi)

CVE-2021-22050

4.x

KB87646 (4.4)

Cloud Foundation (ESXi)

CVE-2021-22050

3.x

3.11

NSX Data Center for vSphere

CVE-2022-22945

ËùÓа汾

6.4.13

 

0x02 ´¦Öý¨Òé

ĿǰÕâЩ©¶´ÒѾ­ÐÞ¸´£¬½¨ÒéÊÜÓ°ÏìÓû§¼°Ê±Éý¼¶¸üС£

ÏÂÔØÁ´½Ó£º

https://www.vmware.com/security/advisories/VMSA-2022-0004.html

https://www.vmware.com/security/advisories/VMSA-2022-0005.html


0x03 ²Î¿¼Á´½Ó

https://www.vmware.com/security/advisories/VMSA-2022-0004.html

https://www.vmware.com/security/advisories/VMSA-2022-0005.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22945

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-02-16

Ê×´ÎÐû²¼

 

 

0x05 ¸½Â¼

¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨¹«Ë¾½¨Á¢ÓÚ1996Ä꣬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬ÊǹúÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÄþ¾²²úÎï¡¢¿ÉÐÅÄþ¾²¹ÜÀíÆ½Ì¨¡¢Äþ¾²·þÎñÓë½â¾ö·½°¸µÄ×ÛºÏÌṩÉÌ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬ÓµÓÐÁýÕÖÈ«¹úµÄÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÖÐÐÄ£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

 

¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º

image.png