Ò»¡¢Â©¶´¸ÅÊö
©¶´Ãû³Æ | VMware ESXi ÈÎÒâдÈë©¶´ |
CVE ID | CVE-2025-22225 |
©¶´ÀàÐÍ | ÈÎÒâдÈë | ·¢ÏÖʱ¼ä | 2025-03-06 |
©¶´ÆÀ·Ö | 8.2 | ©¶´Æ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | µ±µØ | ËùÐèȨÏÞ | ¸ß |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | ÒÑ·¢ÏÖ |
VMware ESXiÊÇVMwareÌṩµÄÆóÒµ¼¶Type-1ÐéÄ⻯¹ÜÀí·¨Ê½£¨Hypervisor£©£¬ÓÃÓÚ·þÎñÆ÷ÐéÄ⻯¡£Ëü»ùÓÚÂã»ú¼Ü¹¹£¬Ö±½ÓÔËÐÐÔÚÎïÀí·þÎñÆ÷ÉÏ£¬ÎÞÐèµ×²ã²Ù×÷ϵͳ£¬Ìṩ¸ßÐÔÄÜ¡¢×ÊÔ´¸ôÀëºÍÄþ¾²ÐÔ¡£ESXiÖ§³ÖÐéÄâ»ú¹ÜÀí¡¢¶¯Ì¬×ÊÔ´µ÷Öμ°¸ß¿ÉÓÃÐÔ£¬¹ã·ºÓ¦ÓÃÓÚÊý¾ÝÖÐÐĺÍÔÆ¼ÆËã»·¾³¡£
2025Äê3ÔÂ6ÈÕ£¬¶«Éƽ̨¼¯ÍÅVSRC¼à²âµ½VMwareÐû²¼ÁËCVE-2025-22225Ïà¹ØÄþ¾²Í¨¸æ¡£Í¨¸æÖ¸³ö£¬VMware ESXi´æÔÚÈÎÒâдÈë©¶´£¬¹¥»÷Õß¿ÉÔÚÌØ¶¨Ìõ¼þÏÂÏòÄÚºËдÈëÊý¾Ý¡£¾ß±¸VMX½ø³ÌȨÏ޵ĶñÒâ¹¥»÷Õ߿ɴ¥·¢Äں˼¶ÈÎÒâдÈ룬´Ó¶øÊµÏÖɳÏäÌÓÒÝ£¨Sandbox Escape£©£¬Í»ÆÆÐéÄ⻯¸ôÀë¡£¸Ã©¶´CVSSv3ÆÀ·Ö8.2£¬Â©¶´Æ·¼¶Îª¸ßΣ¡£
¶þ¡¢Ó°Ï췶Χ
VMware ESXi 8.0 < ESXi80U3d-24585383VMware ESXi 8.0 < ESXi80U2d-24585300VMware ESXi 7.0 < ESXi70U3s-24585291VMware Cloud Foundation 5.x < Òì²½²¹¶¡ESXi80U3d-24585383VMware Cloud Foundation 4.5.x < Òì²½²¹¶¡ESXi70U3s-24585291VMware Telco Cloud Platform 5.x, 4.x, 3.x, 2.x < KB389385VMware Telco Cloud Infrastructure 3.x, 2.x < KB389385
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
Vmware¹Ù·½ÒÑÔÚÈçϰ汾ÖÐÐÞ¸´ÁË´Ë©¶´¡£½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶£¬ÒÔ½â¾ö¸ÃÎÊÌâ¡£
VMware ESXi 8.0 >= ESXi80U3d-24585383VMware ESXi 8.0 >= ESXi80U2d-24585300VMware ESXi 7.0 >= ESXi70U3s-24585291VMware Cloud Foundation 5.x >= Òì²½²¹¶¡ESXi80U3d-24585383VMware Cloud Foundation 4.5.x >= Òì²½²¹¶¡ESXi70U3s-24585291VMware Telco Cloud Platform 5.x, 4.x, 3.x, 2.x >= KB389385VMware Telco Cloud Infrastructure 3.x, 2.x >= KB389385
ÏÂÔØÁ´½Ó£ºhttps://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390/
3.2 ÁÙʱ´ëÊ©
3.3 ͨÓý¨Òé
? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
? ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£? ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£? ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£? ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390https://nvd.nist.gov/vuln/detail/CVE-2025-22225